Edit tour

Windows Analysis Report
ORDER 517-2025.xla.xlsx

Overview

General Information

Sample name:ORDER 517-2025.xla.xlsx
Analysis ID:1649092
MD5:307073b336245bffd54f68919948a0aa
SHA1:eb2877643dfacc68c121e9588ff2774e6e7a80f0
SHA256:13107d3ff9000f73a501043bb4cdca50408dacb5c0cfcd3c1a0b3e9cdd455c43
Tags:xlaxlsxuser-abuse_ch
Infos:

Detection

Score:48
Range:0 - 100
Confidence:100%

Signatures

Multi AV Scanner detection for submitted file
Document contains embedded VBA macros
Document embeds suspicious OLE2 link
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
Potential document exploit detected (performs DNS queries)
Potential document exploit detected (performs HTTP gets)
Potential document exploit detected (unknown TCP traffic)
Sample execution stops while process was sleeping (likely an evasion)
Sigma detected: Excel Network Connections
Sigma detected: Suspicious Office Outbound Connections
Suricata IDS alerts with low severity for network traffic
Unable to load, office file is protected or invalid
Uses a known web browser user agent for HTTP communication

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • EXCEL.EXE (PID: 6192 cmdline: "C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" /automation -Embedding MD5: 4A871771235598812032C822E6F68F19)
    • splwow64.exe (PID: 6724 cmdline: C:\Windows\splwow64.exe 12288 MD5: 77DE7761B037061C7C112FD3C5B91E73)
  • EXCEL.EXE (PID: 5736 cmdline: "C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" "C:\Users\user\Desktop\ORDER 517-2025.xla.xlsx" MD5: 4A871771235598812032C822E6F68F19)
  • cleanup
No configs have been found
No yara matches
Source: Network ConnectionAuthor: Christopher Peacock '@securepeacock', SCYTHE '@scythe_io', Florian Roth '@Neo23x0", Tim Shelton: Data: DestinationIp: 147.79.86.93, DestinationIsIpv6: false, DestinationPort: 443, EventID: 3, Image: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE, Initiated: true, ProcessId: 6192, Protocol: tcp, SourceIp: 192.168.2.12, SourceIsIpv6: false, SourcePort: 49757
Source: Network ConnectionAuthor: X__Junior (Nextron Systems): Data: DestinationIp: 192.168.2.12, DestinationIsIpv6: false, DestinationPort: 49757, EventID: 3, Image: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE, Initiated: true, ProcessId: 6192, Protocol: tcp, SourceIp: 147.79.86.93, SourceIsIpv6: false, SourcePort: 443
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2025-03-26T14:08:56.593919+010020283713Unknown Traffic192.168.2.124975913.107.246.40443TCP
2025-03-26T14:09:04.312411+010020283713Unknown Traffic192.168.2.124976013.107.246.40443TCP
2025-03-26T14:09:04.327093+010020283713Unknown Traffic192.168.2.124976113.107.246.40443TCP

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: ORDER 517-2025.xla.xlsxVirustotal: Detection: 21%Perma Link
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile opened: C:\Program Files (x86)\Microsoft Office\root\vfs\SystemX86\MSVCR100.dllJump to behavior
Source: unknownHTTPS traffic detected: 147.79.86.93:443 -> 192.168.2.12:49757 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.107.246.40:443 -> 192.168.2.12:49759 version: TLS 1.2
Source: global trafficDNS query: name: otelrules.svc.static.microsoft
Source: global trafficDNS query: name: agr.my
Source: global trafficDNS query: name: otelrules.svc.static.microsoft
Source: global trafficTCP traffic: 192.168.2.12:49757 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.12:49758 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49760 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49761 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49757 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.12:49757 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.12:49757 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.12:49757 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.12:49757 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.12:49757 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.12:49757 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.12:49757 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.12:49757 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.12:49757 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.12:49758 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.12:49758 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.12:49758 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.12:49758 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.12:49758 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.12:49758 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.12:49758 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.12:49758 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.12:49758 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.12:49758 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.12:49758 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.12:49758 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.12:49758 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.12:49758 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.12:49758 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49761 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49760 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49761 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49760 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49761 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49760 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49760 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49760 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49761 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49761 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49760 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49760 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49760 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49761 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49761 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49761 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49757 -> 147.79.86.93:443
Source: global trafficTCP traffic: 147.79.86.93:443 -> 192.168.2.12:49757
Source: global trafficTCP traffic: 192.168.2.12:49757 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.12:49757 -> 147.79.86.93:443
Source: global trafficTCP traffic: 147.79.86.93:443 -> 192.168.2.12:49757
Source: global trafficTCP traffic: 147.79.86.93:443 -> 192.168.2.12:49757
Source: global trafficTCP traffic: 192.168.2.12:49757 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.12:49757 -> 147.79.86.93:443
Source: global trafficTCP traffic: 147.79.86.93:443 -> 192.168.2.12:49757
Source: global trafficTCP traffic: 147.79.86.93:443 -> 192.168.2.12:49757
Source: global trafficTCP traffic: 192.168.2.12:49757 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.12:49757 -> 147.79.86.93:443
Source: global trafficTCP traffic: 147.79.86.93:443 -> 192.168.2.12:49757
Source: global trafficTCP traffic: 147.79.86.93:443 -> 192.168.2.12:49757
Source: global trafficTCP traffic: 147.79.86.93:443 -> 192.168.2.12:49757
Source: global trafficTCP traffic: 192.168.2.12:49757 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.12:49757 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.12:49757 -> 147.79.86.93:443
Source: global trafficTCP traffic: 147.79.86.93:443 -> 192.168.2.12:49757
Source: global trafficTCP traffic: 192.168.2.12:49758 -> 147.79.86.93:443
Source: global trafficTCP traffic: 147.79.86.93:443 -> 192.168.2.12:49758
Source: global trafficTCP traffic: 192.168.2.12:49758 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.12:49758 -> 147.79.86.93:443
Source: global trafficTCP traffic: 147.79.86.93:443 -> 192.168.2.12:49758
Source: global trafficTCP traffic: 147.79.86.93:443 -> 192.168.2.12:49758
Source: global trafficTCP traffic: 192.168.2.12:49758 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.12:49758 -> 147.79.86.93:443
Source: global trafficTCP traffic: 147.79.86.93:443 -> 192.168.2.12:49758
Source: global trafficTCP traffic: 192.168.2.12:49758 -> 147.79.86.93:443
Source: global trafficTCP traffic: 147.79.86.93:443 -> 192.168.2.12:49758
Source: global trafficTCP traffic: 147.79.86.93:443 -> 192.168.2.12:49758
Source: global trafficTCP traffic: 192.168.2.12:49758 -> 147.79.86.93:443
Source: global trafficTCP traffic: 147.79.86.93:443 -> 192.168.2.12:49758
Source: global trafficTCP traffic: 192.168.2.12:49758 -> 147.79.86.93:443
Source: global trafficTCP traffic: 147.79.86.93:443 -> 192.168.2.12:49758
Source: global trafficTCP traffic: 192.168.2.12:49758 -> 147.79.86.93:443
Source: global trafficTCP traffic: 147.79.86.93:443 -> 192.168.2.12:49758
Source: global trafficTCP traffic: 192.168.2.12:49758 -> 147.79.86.93:443
Source: global trafficTCP traffic: 147.79.86.93:443 -> 192.168.2.12:49758
Source: global trafficTCP traffic: 147.79.86.93:443 -> 192.168.2.12:49758
Source: global trafficTCP traffic: 192.168.2.12:49758 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.12:49758 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.12:49758 -> 147.79.86.93:443
Source: global trafficTCP traffic: 147.79.86.93:443 -> 192.168.2.12:49758
Source: global trafficTCP traffic: 192.168.2.12:49758 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.12:49758 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49759 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49759
Source: global trafficTCP traffic: 192.168.2.12:49761 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49761
Source: global trafficTCP traffic: 192.168.2.12:49760 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49760
Source: global trafficTCP traffic: 192.168.2.12:49761 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49760 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49761 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49761
Source: global trafficTCP traffic: 192.168.2.12:49760 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49760
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49760
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49761
Source: global trafficTCP traffic: 192.168.2.12:49760 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49760
Source: global trafficTCP traffic: 192.168.2.12:49760 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49760
Source: global trafficTCP traffic: 192.168.2.12:49761 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49761
Source: global trafficTCP traffic: 192.168.2.12:49761 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49761
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49760
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49760
Source: global trafficTCP traffic: 192.168.2.12:49760 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49760
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49760
Source: global trafficTCP traffic: 192.168.2.12:49760 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49761
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49761
Source: global trafficTCP traffic: 192.168.2.12:49760 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49760
Source: global trafficTCP traffic: 192.168.2.12:49761 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49761 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.12:49761 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49761
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.12:49761
Source: Joe Sandbox ViewIP Address: 147.79.86.93 147.79.86.93
Source: Joe Sandbox ViewIP Address: 13.107.246.40 13.107.246.40
Source: Joe Sandbox ViewIP Address: 13.107.246.40 13.107.246.40
Source: Joe Sandbox ViewJA3 fingerprint: 6271f898ce5be7dd52b0fc260d0662b3
Source: Joe Sandbox ViewJA3 fingerprint: a0e9f5d64349fb13191bc781f81f42e1
Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.12:49759 -> 13.107.246.40:443
Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.12:49761 -> 13.107.246.40:443
Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.12:49760 -> 13.107.246.40:443
Source: global trafficHTTP traffic detected: GET /kVTCHC?&thanks HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoHost: agr.myConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /404 HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoHost: agr.myConnection: Keep-Alive
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /kVTCHC?&thanks HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoHost: agr.myConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /404 HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoHost: agr.myConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /rules/excel.exe-Production-v19.bundle HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Excel 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
Source: global trafficHTTP traffic detected: GET /rules/rule120603v8s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Excel 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
Source: global trafficHTTP traffic detected: GET /rules/rule120607v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Excel 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
Source: global trafficDNS traffic detected: DNS query: otelrules.svc.static.microsoft
Source: global trafficDNS traffic detected: DNS query: agr.my
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundContent-Type: text/html; charset=utf-8Date: Wed, 26 Mar 2025 13:08:43 GMTEtag: "1225-4lR+8o8+z0M1Iq6OMuNgxAtPjT8"Strict-Transport-Security: max-age=15552000; includeSubDomainsVary: Accept-EncodingX-Content-Type-Options: nosniffX-Dns-Prefetch-Control: offX-Download-Options: noopenX-Frame-Options: SAMEORIGINX-Powered-By: Next.jsX-Xss-Protection: 1; mode=blockConnection: closeTransfer-Encoding: chunked
Source: ORDER 517-2025.xla.xlsxString found in binary or memory: https://agr.my/kVTCHC?&thanks
Source: unknownNetwork traffic detected: HTTP traffic on port 49757 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49758 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49761
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49760
Source: unknownNetwork traffic detected: HTTP traffic on port 49761 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49760 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49759
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49758
Source: unknownNetwork traffic detected: HTTP traffic on port 49759 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49757
Source: unknownHTTPS traffic detected: 147.79.86.93:443 -> 192.168.2.12:49757 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.107.246.40:443 -> 192.168.2.12:49759 version: TLS 1.2
Source: ORDER 517-2025.xla.xlsxOLE indicator, VBA macros: true
Source: ORDER 517-2025.xla.xlsxStream path 'MBD00EB272B/\x1Ole' : https://agr.my/kVTCHC?&thanksl\%i7L20,G&KRms`RaHDd%<=&}BYB;``Ia2/NyK8:I-*%yH_9>^-}%P`.'?[Wpuo\.<hBoA#OA~5<[CO`~6a0<CL49FyTKpDUmqyMl4SS40moMSKeee3Sf2dJiMthNQRhDcoyuODJZidkG4VcTGrr2fRLHFZ70A3Suw9ffBYvQHYdRrzkWlwAXzu0uAh282EEHuyyer2btileJqvZpMKERguLrp5HMoslvl67uZw15HmYdt8pRf6Yfb7TJFsaoPhnRS5x4TGsIqMkqcDYSipWVEwjYxW9BPJLS7V3Jdn8nffJpp>r2iOJwwvf;Y7t
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEWindow title found: microsoft excel okexcel cannot open the file 'order 517-2025.xla.xlsx' because the file format or file extension is not valid. verify that the file has not been corrupted and that the file extension matches the format of the file.
Source: classification engineClassification label: mal48.winXLSX@4/4@3/2
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile created: C:\Program Files (x86)\Microsoft Office\root\vfs\Common AppData\Microsoft\Office\Heartbeat\HeartbeatCache.xmlJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile created: C:\Users\user\Desktop\~$ORDER 517-2025.xla.xlsxJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Temp\{A70B247B-2673-4A7C-B36D-36F52E1BA083} - OProcSessId.datJump to behavior
Source: ORDER 517-2025.xla.xlsxOLE indicator, Workbook stream: true
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile read: C:\Users\desktop.iniJump to behavior
Source: ORDER 517-2025.xla.xlsxVirustotal: Detection: 21%
Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" /automation -Embedding
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288
Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" "C:\Users\user\Desktop\ORDER 517-2025.xla.xlsx"
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{3EE60F5C-9BAD-4CD8-8E21-AD2D001D06EB}\InprocServer32Jump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\CommonJump to behavior
Source: ORDER 517-2025.xla.xlsxStatic file information: File size 1247744 > 1048576
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile opened: C:\Program Files (x86)\Microsoft Office\root\vfs\SystemX86\MSVCR100.dllJump to behavior
Source: ORDER 517-2025.xla.xlsxInitial sample: OLE indicators encrypted = True
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: ORDER 517-2025.xla.xlsxStream path 'MBD00EB272A/Package' entropy: 7.9725327182 (max. 8.0)
Source: ORDER 517-2025.xla.xlsxStream path 'Workbook' entropy: 7.9989836689 (max. 8.0)
Source: C:\Windows\splwow64.exeWindow / User API: threadDelayed 808Jump to behavior
Source: C:\Windows\splwow64.exeLast function: Thread delayed
Source: C:\Windows\splwow64.exeLast function: Thread delayed
Source: C:\Windows\splwow64.exeThread delayed: delay time: 120000Jump to behavior
Source: C:\Windows\splwow64.exeThread delayed: delay time: 120000Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information queried: ProcessInformationJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity Information1
Scripting
Valid Accounts3
Exploitation for Client Execution
1
Scripting
1
Process Injection
2
Masquerading
OS Credential Dumping1
Process Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Virtualization/Sandbox Evasion
LSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable Media3
Ingress Tool Transfer
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
Process Injection
Security Account Manager1
Application Window Discovery
SMB/Windows Admin SharesData from Network Shared Drive3
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Obfuscated Files or Information
NTDS1
File and Directory Discovery
Distributed Component Object ModelInput Capture14
Application Layer Protocol
Traffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon ScriptSoftware PackingLSA Secrets1
System Information Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1649092 Sample: ORDER 517-2025.xla.xlsx Startdate: 26/03/2025 Architecture: WINDOWS Score: 48 17 star-azurefd-prod.trafficmanager.net 2->17 19 shed.dual-low.s-part-0012.t-0009.t-msedge.net 2->19 21 8 other IPs or domains 2->21 27 Multi AV Scanner detection for submitted file 2->27 7 EXCEL.EXE 227 57 2->7         started        11 EXCEL.EXE 53 47 2->11         started        signatures3 process4 dnsIp5 23 s-part-0012.t-0009.t-msedge.net 13.107.246.40, 443, 49759, 49760 MICROSOFT-CORP-MSN-AS-BLOCKUS United States 7->23 25 agr.my 147.79.86.93, 443, 49757, 49758 EKSENBILISIMTR United States 7->25 15 C:\Users\user\...\~$ORDER 517-2025.xla.xlsx, data 7->15 dropped 13 splwow64.exe 1 7->13         started        file6 process7

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
ORDER 517-2025.xla.xlsx22%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://agr.my/kVTCHC?&thanks0%Avira URL Cloudsafe
https://agr.my/4040%Avira URL Cloudsafe

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
s-part-0010.t-0009.t-msedge.net
13.107.246.38
truefalse
    high
    s-part-0012.t-0009.t-msedge.net
    13.107.246.40
    truefalse
      high
      agr.my
      147.79.86.93
      truefalse
        high
        s-0005.dual-s-msedge.net
        52.123.128.14
        truefalse
          high
          otelrules.svc.static.microsoft
          unknown
          unknownfalse
            high
            NameMaliciousAntivirus DetectionReputation
            https://otelrules.svc.static.microsoft/rules/excel.exe-Production-v19.bundlefalse
              high
              https://agr.my/kVTCHC?&thanksfalse
              • Avira URL Cloud: safe
              unknown
              https://agr.my/404false
              • Avira URL Cloud: safe
              unknown
              https://otelrules.svc.static.microsoft/rules/rule120607v1s19.xmlfalse
                high
                https://otelrules.svc.static.microsoft/rules/rule120603v8s19.xmlfalse
                  high
                  • No. of IPs < 25%
                  • 25% < No. of IPs < 50%
                  • 50% < No. of IPs < 75%
                  • 75% < No. of IPs
                  IPDomainCountryFlagASNASN NameMalicious
                  147.79.86.93
                  agr.myUnited States
                  208485EKSENBILISIMTRfalse
                  13.107.246.40
                  s-part-0012.t-0009.t-msedge.netUnited States
                  8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                  Joe Sandbox version:42.0.0 Malachite
                  Analysis ID:1649092
                  Start date and time:2025-03-26 14:05:52 +01:00
                  Joe Sandbox product:CloudBasic
                  Overall analysis duration:0h 5m 55s
                  Hypervisor based Inspection enabled:false
                  Report type:full
                  Cookbook file name:defaultwindowsofficecookbook.jbs
                  Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                  Number of analysed new started processes analysed:11
                  Number of new started drivers analysed:0
                  Number of existing processes analysed:0
                  Number of existing drivers analysed:0
                  Number of injected processes analysed:0
                  Technologies:
                  • HCA enabled
                  • EGA enabled
                  • GSI enabled (VBA)
                  • AMSI enabled
                  Analysis Mode:default
                  Analysis stop reason:Timeout
                  Sample name:ORDER 517-2025.xla.xlsx
                  Detection:MAL
                  Classification:mal48.winXLSX@4/4@3/2
                  EGA Information:Failed
                  HCA Information:
                  • Successful, ratio: 100%
                  • Number of executed functions: 0
                  • Number of non-executed functions: 0
                  Cookbook Comments:
                  • Found application associated with file extension: .xlsx
                  • Found Word or Excel or PowerPoint or XPS Viewer
                  • Attach to Office via COM
                  • Active ActiveX Object
                  • Active ActiveX Object
                  • Scroll down
                  • Close Viewer
                  • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, sppsvc.exe, WMIADAP.exe, conhost.exe, svchost.exe
                  • Excluded IPs from analysis (whitelisted): 52.109.32.97, 52.109.8.36, 184.31.69.3, 20.42.65.90, 20.42.73.26, 52.149.20.212, 52.123.128.14, 40.126.24.82
                  • Excluded domains from analysis (whitelisted): slscr.update.microsoft.com, onedscolprdeus14.eastus.cloudapp.azure.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, e16604.dscf.akamaiedge.net, mobile.events.data.microsoft.com, roaming.officeapps.live.com, osiprod-cus-buff-azsc-000.centralus.cloudapp.azure.com, dual-s-0005-office.config.skype.com, login.live.com, onedscolprdeus09.eastus.cloudapp.azure.com, officeclient.microsoft.com, ukw-azsc-config.officeapps.live.com, prod.fs.microsoft.com.akadns.net, c.pki.goog, ecs.office.com, self-events-data.trafficmanager.net, fs.microsoft.com, prod.configsvc1.live.com.akadns.net, self.events.data.microsoft.com, ctldl.windowsupdate.com, prod.roaming1.live.com.akadns.net, cus-azsc-000.roaming.officeapps.live.com, fe3cr.delivery.mp.microsoft.com, us1.roaming1.live.com.akadns.net, config.officeapps.live.com, ecs.office.trafficmanager.net, europe.configsvc1.live.com.akadns.net, mobile.events.data.trafficmanager.net
                  • Not all processes where analyzed, report is missing behavior information
                  • Report size getting too big, too many NtCreateKey calls found.
                  • Report size getting too big, too many NtQueryAttributesFile calls found.
                  • Report size getting too big, too many NtQueryValueKey calls found.
                  • Report size getting too big, too many NtReadVirtualMemory calls found.
                  • Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                  TimeTypeDescription
                  09:08:50API Interceptor833x Sleep call for process: splwow64.exe modified
                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                  147.79.86.93MDRHZBOL2477518 CO.xlsGet hashmaliciousUnknownBrowse
                    Merged documents.docx.docGet hashmaliciousUnknownBrowse
                      MDRHZBOL2477518 CO.xlsGet hashmaliciousUnknownBrowse
                        Merged documents.docx.docGet hashmaliciousUnknownBrowse
                          ORDER 517-2025.xla.xlsxGet hashmaliciousUnknownBrowse
                            ORDER 517-2025.xla.xlsxGet hashmaliciousUnknownBrowse
                              Transferencia de pago.xla.xlsxGet hashmaliciousUnknownBrowse
                                ORDER 517-2025.xla.xlsxGet hashmaliciousUnknownBrowse
                                  Transferencia de pago.xla.xlsxGet hashmaliciousUnknownBrowse
                                    Transferencia de pago.xla.xlsxGet hashmaliciousUnknownBrowse
                                      13.107.246.40Payment Transfer Receipt.shtmlGet hashmaliciousHTMLPhisherBrowse
                                      • www.aib.gov.uk/
                                      NEW ORDER.xlsGet hashmaliciousUnknownBrowse
                                      • 2s.gg/3zs
                                      PO_OCF 408.xlsGet hashmaliciousUnknownBrowse
                                      • 2s.gg/42Q
                                      06836722_218 Aluplast.docx.docGet hashmaliciousUnknownBrowse
                                      • 2s.gg/3zk
                                      Quotation.xlsGet hashmaliciousUnknownBrowse
                                      • 2s.gg/3zM
                                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                      s-0005.dual-s-msedge.netChristian.msgGet hashmaliciousUnknownBrowse
                                      • 52.123.129.14
                                      https://onedrive.live.com/:o:/g/personal/A19E0D27A159B01D/EjrRUOhvrVRPjf7frmHTxHoBOP8hIZH3Py3RVZphI8BRhg?resid=A19E0D27A159B01D!se850d13aad6f4f548dfedfae61d3c47a&ithint=onenote&e=VRLCee&migratedtospo=true&redeem=aHR0cHM6Ly8xZHJ2Lm1zL28vYy9hMTllMGQyN2ExNTliMDFkL0VqclJVT2h2clZSUGpmN2ZybUhUeEhvQk9QOGhJWkgzUHkzUlZacGhJOEJSaGc_ZT1WUkxDZWUGet hashmaliciousUnknownBrowse
                                      • 52.123.129.14
                                      https://mwrelocation-my.sharepoint.com/:o:/g/personal/mark_muss_mwrelo_com/EpQqkTDGaCBAnjTdG-zDbx0BUBQDo-hUhmePP1xfEWwUaQ?e=5%3ak0pMsO&at=9&xsdata=MDV8MDJ8cm9ubmllLmR1bmNhbkBrMmNvcnBvcmF0ZW1vYmlsaXR5LmNvbXw2NzI0MTRlN2FkNzk0ZTIwNTc0ZjA4ZGQ2YzU1ZjVkMXwzZTg3NTEyOTZjNjU0MmE1OTMxNjQ3ZTQzNDA2NWI1YnwwfDB8NjM4Nzg1ODM4OTIzNDgzODQ3fFVua25vd258VFdGcGJHWnNiM2Q4ZXlKRmJYQjBlVTFoY0draU9uUnlkV1VzSWxZaU9pSXdMakF1TURBd01DSXNJbEFpT2lKWGFXNHpNaUlzSWtGT0lqb2lUV0ZwYkNJc0lsZFVJam95ZlE9PXwyMDAwMHx8fA%3d%3d&sdata=eEQ4emMvM2xjQmFCdG5tT1Y0VjVjVlJoUWltV3l0aGdNTXNyaElXWGY4az0%3dGet hashmaliciousUnknownBrowse
                                      • 52.123.129.14
                                      MDRHZBOL2477518 CO.xlsGet hashmaliciousUnknownBrowse
                                      • 52.123.129.14
                                      ORDER 517-2025.xla.xlsxGet hashmaliciousUnknownBrowse
                                      • 52.123.128.14
                                      MDRHZBOL2477518 CO.xlsGet hashmaliciousUnknownBrowse
                                      • 52.123.129.14
                                      Merged documents.docx.docGet hashmaliciousUnknownBrowse
                                      • 52.123.129.14
                                      ORDER 517-2025.xla.xlsxGet hashmaliciousUnknownBrowse
                                      • 52.123.128.14
                                      Filled Summons Notice.docxGet hashmaliciousUnknownBrowse
                                      • 52.123.129.14
                                      DanielEmployee-Handbook-84408.docGet hashmaliciousGabagoolBrowse
                                      • 52.123.129.14
                                      s-part-0010.t-0009.t-msedge.nethttps://onedrive.live.com/:o:/g/personal/A19E0D27A159B01D/EjrRUOhvrVRPjf7frmHTxHoBOP8hIZH3Py3RVZphI8BRhg?resid=A19E0D27A159B01D!se850d13aad6f4f548dfedfae61d3c47a&ithint=onenote&e=VRLCee&migratedtospo=true&redeem=aHR0cHM6Ly8xZHJ2Lm1zL28vYy9hMTllMGQyN2ExNTliMDFkL0VqclJVT2h2clZSUGpmN2ZybUhUeEhvQk9QOGhJWkgzUHkzUlZacGhJOEJSaGc_ZT1WUkxDZWUGet hashmaliciousUnknownBrowse
                                      • 13.107.246.38
                                      MDRHZBOL2477518 CO.xlsGet hashmaliciousUnknownBrowse
                                      • 13.107.246.38
                                      Proforma invoice.xlsGet hashmaliciousUnknownBrowse
                                      • 13.107.246.38
                                      ORDER 517-2025.xla.xlsxGet hashmaliciousUnknownBrowse
                                      • 13.107.246.38
                                      EwZAaQu0yXKbde7.exeGet hashmaliciousAsyncRAT, PureLog Stealer, XWormBrowse
                                      • 13.107.246.38
                                      https://proposaldocumentsviasecuredport.com/ZayUC/?email=john.smith%40microsoft.comGet hashmaliciousHTMLPhisherBrowse
                                      • 13.107.246.38
                                      Play Voicemail Transcription. (387.KB).svgGet hashmaliciousHTMLPhisherBrowse
                                      • 13.107.246.38
                                      EFT Remittance_(Bobd)CQDM.htmGet hashmaliciousHTMLPhisher, Invisible JS, Tycoon2FABrowse
                                      • 13.107.246.38
                                      PURCHASE ORDER 5172025.xla.xlsxGet hashmaliciousUnknownBrowse
                                      • 13.107.246.38
                                      #Ud83d#Udd0aAudio_Msg Junklessfoods.xhtmlGet hashmaliciousHTMLPhisherBrowse
                                      • 13.107.246.38
                                      agr.myMDRHZBOL2477518 CO.xlsGet hashmaliciousUnknownBrowse
                                      • 147.79.86.93
                                      Merged documents.docx.docGet hashmaliciousUnknownBrowse
                                      • 147.79.86.93
                                      MDRHZBOL2477518 CO.xlsGet hashmaliciousUnknownBrowse
                                      • 147.79.86.93
                                      Merged documents.docx.docGet hashmaliciousUnknownBrowse
                                      • 147.79.86.93
                                      ORDER 517-2025.xla.xlsxGet hashmaliciousUnknownBrowse
                                      • 147.79.86.93
                                      ORDER 517-2025.xla.xlsxGet hashmaliciousUnknownBrowse
                                      • 147.79.86.93
                                      Transferencia de pago.xla.xlsxGet hashmaliciousUnknownBrowse
                                      • 147.79.86.93
                                      ORDER 517-2025.xla.xlsxGet hashmaliciousUnknownBrowse
                                      • 147.79.86.93
                                      Transferencia de pago.xla.xlsxGet hashmaliciousUnknownBrowse
                                      • 147.79.86.93
                                      Transferencia de pago.xla.xlsxGet hashmaliciousUnknownBrowse
                                      • 147.79.86.93
                                      s-part-0012.t-0009.t-msedge.nethttps://onedrive.live.com/:o:/g/personal/A19E0D27A159B01D/EjrRUOhvrVRPjf7frmHTxHoBOP8hIZH3Py3RVZphI8BRhg?resid=A19E0D27A159B01D!se850d13aad6f4f548dfedfae61d3c47a&ithint=onenote&e=VRLCee&migratedtospo=true&redeem=aHR0cHM6Ly8xZHJ2Lm1zL28vYy9hMTllMGQyN2ExNTliMDFkL0VqclJVT2h2clZSUGpmN2ZybUhUeEhvQk9QOGhJWkgzUHkzUlZacGhJOEJSaGc_ZT1WUkxDZWUGet hashmaliciousUnknownBrowse
                                      • 13.107.246.40
                                      https://mwrelocation-my.sharepoint.com/:o:/g/personal/mark_muss_mwrelo_com/EpQqkTDGaCBAnjTdG-zDbx0BUBQDo-hUhmePP1xfEWwUaQ?e=5%3ak0pMsO&at=9&xsdata=MDV8MDJ8cm9ubmllLmR1bmNhbkBrMmNvcnBvcmF0ZW1vYmlsaXR5LmNvbXw2NzI0MTRlN2FkNzk0ZTIwNTc0ZjA4ZGQ2YzU1ZjVkMXwzZTg3NTEyOTZjNjU0MmE1OTMxNjQ3ZTQzNDA2NWI1YnwwfDB8NjM4Nzg1ODM4OTIzNDgzODQ3fFVua25vd258VFdGcGJHWnNiM2Q4ZXlKRmJYQjBlVTFoY0draU9uUnlkV1VzSWxZaU9pSXdMakF1TURBd01DSXNJbEFpT2lKWGFXNHpNaUlzSWtGT0lqb2lUV0ZwYkNJc0lsZFVJam95ZlE9PXwyMDAwMHx8fA%3d%3d&sdata=eEQ4emMvM2xjQmFCdG5tT1Y0VjVjVlJoUWltV3l0aGdNTXNyaElXWGY4az0%3dGet hashmaliciousUnknownBrowse
                                      • 13.107.246.40
                                      MDRHZBOL2477518 CO.xlsGet hashmaliciousUnknownBrowse
                                      • 13.107.246.40
                                      ORDER 517-2025.xla.xlsxGet hashmaliciousUnknownBrowse
                                      • 13.107.246.40
                                      ORDER 517-2025.xla.xlsxGet hashmaliciousUnknownBrowse
                                      • 13.107.246.40
                                      Distribution_notice8770404590.pdfGet hashmaliciousHTMLPhisherBrowse
                                      • 13.107.246.40
                                      ORDER 517-2025.xla.xlsxGet hashmaliciousUnknownBrowse
                                      • 13.107.246.40
                                      ORDER 517-2025.xla.xlsxGet hashmaliciousUnknownBrowse
                                      • 13.107.246.40
                                      E1AcRCtgSA.exeGet hashmaliciousUnknownBrowse
                                      • 13.107.246.40
                                      Transferencia de pago.xla.xlsxGet hashmaliciousUnknownBrowse
                                      • 13.107.246.40
                                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                      EKSENBILISIMTRMDRHZBOL2477518 CO.xlsGet hashmaliciousUnknownBrowse
                                      • 147.79.86.93
                                      Merged documents.docx.docGet hashmaliciousUnknownBrowse
                                      • 147.79.86.93
                                      MDRHZBOL2477518 CO.xlsGet hashmaliciousUnknownBrowse
                                      • 147.79.86.93
                                      Merged documents.docx.docGet hashmaliciousUnknownBrowse
                                      • 147.79.86.93
                                      ORDER 517-2025.xla.xlsxGet hashmaliciousUnknownBrowse
                                      • 147.79.86.93
                                      ORDER 517-2025.xla.xlsxGet hashmaliciousUnknownBrowse
                                      • 147.79.86.93
                                      Transferencia de pago.xla.xlsxGet hashmaliciousUnknownBrowse
                                      • 147.79.86.93
                                      ORDER 517-2025.xla.xlsxGet hashmaliciousUnknownBrowse
                                      • 147.79.86.93
                                      Transferencia de pago.xla.xlsxGet hashmaliciousUnknownBrowse
                                      • 147.79.86.93
                                      Transferencia de pago.xla.xlsxGet hashmaliciousUnknownBrowse
                                      • 147.79.86.93
                                      MICROSOFT-CORP-MSN-AS-BLOCKUShttps://forms.office.com/r/d0xrd5MNWnGet hashmaliciousInvisible JS, Tycoon2FABrowse
                                      • 20.110.205.119
                                      https://onedrive.live.com/:o:/g/personal/A19E0D27A159B01D/EjrRUOhvrVRPjf7frmHTxHoBOP8hIZH3Py3RVZphI8BRhg?resid=A19E0D27A159B01D!se850d13aad6f4f548dfedfae61d3c47a&ithint=onenote&e=VRLCee&migratedtospo=true&redeem=aHR0cHM6Ly8xZHJ2Lm1zL28vYy9hMTllMGQyN2ExNTliMDFkL0VqclJVT2h2clZSUGpmN2ZybUhUeEhvQk9QOGhJWkgzUHkzUlZacGhJOEJSaGc_ZT1WUkxDZWUGet hashmaliciousUnknownBrowse
                                      • 52.111.229.20
                                      https://mwrelocation-my.sharepoint.com/:o:/g/personal/mark_muss_mwrelo_com/EpQqkTDGaCBAnjTdG-zDbx0BUBQDo-hUhmePP1xfEWwUaQ?e=5%3ak0pMsO&at=9&xsdata=MDV8MDJ8cm9ubmllLmR1bmNhbkBrMmNvcnBvcmF0ZW1vYmlsaXR5LmNvbXw2NzI0MTRlN2FkNzk0ZTIwNTc0ZjA4ZGQ2YzU1ZjVkMXwzZTg3NTEyOTZjNjU0MmE1OTMxNjQ3ZTQzNDA2NWI1YnwwfDB8NjM4Nzg1ODM4OTIzNDgzODQ3fFVua25vd258VFdGcGJHWnNiM2Q4ZXlKRmJYQjBlVTFoY0draU9uUnlkV1VzSWxZaU9pSXdMakF1TURBd01DSXNJbEFpT2lKWGFXNHpNaUlzSWtGT0lqb2lUV0ZwYkNJc0lsZFVJam95ZlE9PXwyMDAwMHx8fA%3d%3d&sdata=eEQ4emMvM2xjQmFCdG5tT1Y0VjVjVlJoUWltV3l0aGdNTXNyaElXWGY4az0%3dGet hashmaliciousUnknownBrowse
                                      • 52.111.229.20
                                      MDRHZBOL2477518 CO.xlsGet hashmaliciousUnknownBrowse
                                      • 13.107.246.40
                                      ORDER 517-2025.xla.xlsxGet hashmaliciousUnknownBrowse
                                      • 13.107.246.40
                                      MDRHZBOL2477518 CO.xlsGet hashmaliciousUnknownBrowse
                                      • 13.107.246.38
                                      ORDER 517-2025.xla.xlsxGet hashmaliciousUnknownBrowse
                                      • 13.107.246.40
                                      http://support.delfi.comGet hashmaliciousUnknownBrowse
                                      • 52.96.239.178
                                      frosty.x86.elfGet hashmaliciousUnknownBrowse
                                      • 20.61.249.252
                                      frosty.arm.elfGet hashmaliciousUnknownBrowse
                                      • 20.136.162.125
                                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                      6271f898ce5be7dd52b0fc260d0662b3MDRHZBOL2477518 CO.xlsGet hashmaliciousUnknownBrowse
                                      • 147.79.86.93
                                      Merged documents.docx.docGet hashmaliciousUnknownBrowse
                                      • 147.79.86.93
                                      ORDER 517-2025.xla.xlsxGet hashmaliciousUnknownBrowse
                                      • 147.79.86.93
                                      ORDER 517-2025.xla.xlsxGet hashmaliciousUnknownBrowse
                                      • 147.79.86.93
                                      Proforma invoice.xlsGet hashmaliciousUnknownBrowse
                                      • 147.79.86.93
                                      Transferencia de pago.xla.xlsxGet hashmaliciousUnknownBrowse
                                      • 147.79.86.93
                                      ORDER 517-2025.xla.xlsxGet hashmaliciousUnknownBrowse
                                      • 147.79.86.93
                                      Proforma invoice.xlsGet hashmaliciousUnknownBrowse
                                      • 147.79.86.93
                                      Transferencia de pago.xla.xlsxGet hashmaliciousUnknownBrowse
                                      • 147.79.86.93
                                      PURCHASE ORDER 5172025.xla.xlsxGet hashmaliciousUnknownBrowse
                                      • 147.79.86.93
                                      a0e9f5d64349fb13191bc781f81f42e1ZczI7LNpUU.exeGet hashmaliciousLummaC StealerBrowse
                                      • 13.107.246.40
                                      MDRHZBOL2477518 CO.xlsGet hashmaliciousUnknownBrowse
                                      • 13.107.246.40
                                      Merged documents.docx.docGet hashmaliciousUnknownBrowse
                                      • 13.107.246.40
                                      ORDER 517-2025.xla.xlsxGet hashmaliciousUnknownBrowse
                                      • 13.107.246.40
                                      ORDER 517-2025.xla.xlsxGet hashmaliciousUnknownBrowse
                                      • 13.107.246.40
                                      E1AcRCtgSA.exeGet hashmaliciousUnknownBrowse
                                      • 13.107.246.40
                                      Proforma invoice.xlsGet hashmaliciousUnknownBrowse
                                      • 13.107.246.40
                                      Transferencia de pago.xla.xlsxGet hashmaliciousUnknownBrowse
                                      • 13.107.246.40
                                      ORDER 517-2025.xla.xlsxGet hashmaliciousUnknownBrowse
                                      • 13.107.246.40
                                      Proforma invoice.xlsGet hashmaliciousUnknownBrowse
                                      • 13.107.246.40
                                      No context
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                                      File Type:XML 1.0 document, Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                      Category:dropped
                                      Size (bytes):118
                                      Entropy (8bit):3.5700810731231707
                                      Encrypted:false
                                      SSDEEP:3:QaklTlAlXMLLmHlIlFLlmIK/5lTn84vlJlhlXlDHlA6l3l6Als:QFulcLk04/5p8GVz6QRq
                                      MD5:573220372DA4ED487441611079B623CD
                                      SHA1:8F9D967AC6EF34640F1F0845214FBC6994C0CB80
                                      SHA-256:BE84B842025E4241BFE0C9F7B8F86A322E4396D893EF87EA1E29C74F47B6A22D
                                      SHA-512:F19FA3583668C3AF92A9CEF7010BD6ECEC7285F9C8665F2E9528DBA606F105D9AF9B1DB0CF6E7F77EF2E395943DC0D5CB37149E773319078688979E4024F9DD7
                                      Malicious:false
                                      Reputation:high, very likely benign file
                                      Preview:..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".U.T.F.-.1.6.".?.>.....<.H.e.a.r.t.b.e.a.t.C.a.c.h.e./.>.
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):784
                                      Entropy (8bit):2.7137690747287806
                                      Encrypted:false
                                      SSDEEP:12:YIrxA3rOpKmA4RP7EcJBSiGl6s8ACn2QYKrn2GpQPZRprw+25WHWspMSp:YIrcSpKmNRwcfHGF8A8iWxKZR++2IHWI
                                      MD5:96F26AC9D00AF170C209932485A93F1B
                                      SHA1:E103D165A1E529CA08D98391E050175C4492BB92
                                      SHA-256:A370505E61C2FB7827705A4875890DBB0DB3A232514AA75FE99E5A637602D230
                                      SHA-512:FF680B0C42CC7918DB73ED715841F9AC1DAB27EF10E44101A3ED63A61A03725CF86F02D06A39BB0BA7C4F5EF5635EAB4D0B60F2A1538781D7A94112C9AF2674E
                                      Malicious:false
                                      Reputation:low
                                      Preview:3.7.4.6.3.7.6.,.1.1.9.6.3.7.8.,.1.7.8.8.6.5.8.,.1.2.5.,.2.5.5.0.5.0.8.8.,.1.1.9.,.3.0.0.4.9.2.6.8.,.;.3.7.4.6.3.7.8.,.3.2.9.4.5.8.7.9.9.,.6.3.6.4.3.3.4.,.3.0.1.5.3.7.2.1.,.2.3.7.1.6.5.1.,.6.5.4.0.2.1.5.,.2.4.6.0.9.2.5.8.,.4.0.6.9.3.5.8.2.,.1.0.4.9.5.2.3.4.,.6.3.6.4.3.1.8.,.3.0.1.2.3.4.6.6.,.2.7.1.5.3.4.9.7.,.6.3.7.1.6.9.4.,.5.9.2.2.3.4.2.3.,.5.7.9.9.9.6.6.1.,.1.5.6.1.9.5.8.,.6.3.0.6.3.0.9.9.,.2.7.3.6.0.0.9.5.,.5.8.4.2.5.8.6.0.,.6.3.6.4.3.3.7.,.6.1.7.0.7.3.0.7.,.6.3.6.4.3.3.0.,.6.3.6.4.3.3.1.,.6.7.4.8.3.9.6.1.4.,.3.3.7.9.1.6.2.,.1.6.5.7.4.5.2.,.1.0.6.9.5.5.2.,.1.6.5.7.4.5.3.,.4.7.3.8.2.9.4.8.,.5.2.9.1.0.0.0.0.,.1.3.5.2.5.8.6.,.1.3.5.2.5.8.7.,.1.7.7.1.6.5.7.,.1.0.2.3.8.6.4.,.6.3.7.1.6.9.5.,.4.8.1.9.5.5.3.8.,.1.0.2.3.6.3.8.,.1.4.6.1.9.5.3.,.6.3.6.4.3.3.2.,.3.2.0.5.9.2.7.6.7.,.
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):512
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:3::
                                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                                      Malicious:false
                                      Reputation:high, very likely benign file
                                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):165
                                      Entropy (8bit):1.4377382811115937
                                      Encrypted:false
                                      SSDEEP:3:BJbFFFjpQl2fV:/bFFFNQlS
                                      MD5:037948E5945313159DC8146EB7973386
                                      SHA1:4CEF8EE5AF61A21ADB398F6C296F48242158A1AA
                                      SHA-256:E63CBDD61699DD98D41777B269B57916B6E67F51E457D71BF62E8BD56D1362E4
                                      SHA-512:E2D94EEDAD02B0D8B478DA100F753608C6A3A49E37FB53E11815CEA7806DF045DF96D5C53E41A4AD9B772A63FDF180FFEB2F49078334AB3C267FAC26E3B21F01
                                      Malicious:true
                                      Preview:.user ..a.l.b.u.s. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                      File type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1252, Name of Creating Application: Microsoft Excel, Create Time/Date: Sat Sep 16 01:00:00 2006, Last Saved Time/Date: Wed Mar 26 06:26:02 2025, Security: 1
                                      Entropy (8bit):7.9729841023173265
                                      TrID:
                                      • Microsoft Excel sheet (30009/1) 47.99%
                                      • Microsoft Excel sheet (alternate) (24509/1) 39.20%
                                      • Generic OLE2 / Multistream Compound File (8008/1) 12.81%
                                      File name:ORDER 517-2025.xla.xlsx
                                      File size:1'247'744 bytes
                                      MD5:307073b336245bffd54f68919948a0aa
                                      SHA1:eb2877643dfacc68c121e9588ff2774e6e7a80f0
                                      SHA256:13107d3ff9000f73a501043bb4cdca50408dacb5c0cfcd3c1a0b3e9cdd455c43
                                      SHA512:351494bea7f8af1a5902a858f496efa4a1ac5b755252485e1604ed1439787d4bc2fb599d6632c5d666bc20a3cda0dde26021eb648d963b0de6241616354d3926
                                      SSDEEP:24576:tv2A6lUE6UzfYti5u0s38xN4XZs4z84W9Gtyct8mDubxhz6u2+wTQw:h2AIUE6KfYtGo38xuX+2WUtyct5D6dPL
                                      TLSH:C0452359B9989F17D5CDD97C1CC28BF7022C6D01B683D5AB2B50B31DBAB87A012C60BD
                                      File Content Preview:........................>...................................B...................................................................E.......g.......i..............................................................................................................
                                      Icon Hash:35e58a8c0c8a85b9
                                      Document Type:OLE
                                      Number of OLE Files:1
                                      Has Summary Info:
                                      Application Name:Microsoft Excel
                                      Encrypted Document:True
                                      Contains Word Document Stream:False
                                      Contains Workbook/Book Stream:True
                                      Contains PowerPoint Document Stream:False
                                      Contains Visio Document Stream:False
                                      Contains ObjectPool Stream:False
                                      Flash Objects Count:0
                                      Contains VBA Macros:True
                                      Code Page:1252
                                      Author:
                                      Last Saved By:
                                      Create Time:2006-09-16 00:00:00
                                      Last Saved Time:2025-03-26 06:26:02
                                      Creating Application:Microsoft Excel
                                      Security:1
                                      Document Code Page:1252
                                      Thumbnail Scaling Desired:False
                                      Contains Dirty Links:False
                                      Shared Document:False
                                      Changed Hyperlinks:False
                                      Application Version:786432
                                      General
                                      Stream Path:_VBA_PROJECT_CUR/VBA/Sheet1
                                      VBA File Name:Sheet1.cls
                                      Stream Size:977
                                      Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1 z f . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 2 . 0 . -
                                      Data Raw:01 16 01 00 00 f0 00 00 00 c4 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff cb 02 00 00 1f 03 00 00 00 00 00 00 01 00 00 00 31 7a 66 85 00 00 ff ff 23 01 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                                      Attribute VB_Name = "Sheet1"
                                      Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"
                                      Attribute VB_GlobalNameSpace = False
                                      Attribute VB_Creatable = False
                                      Attribute VB_PredeclaredId = True
                                      Attribute VB_Exposed = True
                                      Attribute VB_TemplateDerived = False
                                      Attribute VB_Customizable = True
                                      

                                      General
                                      Stream Path:_VBA_PROJECT_CUR/VBA/Sheet2
                                      VBA File Name:Sheet2.cls
                                      Stream Size:977
                                      Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1 z . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 2 . 0 . - .
                                      Data Raw:01 16 01 00 00 f0 00 00 00 c4 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff cb 02 00 00 1f 03 00 00 00 00 00 00 01 00 00 00 31 7a b5 dc 00 00 ff ff 23 01 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                                      Attribute VB_Name = "Sheet2"
                                      Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"
                                      Attribute VB_GlobalNameSpace = False
                                      Attribute VB_Creatable = False
                                      Attribute VB_PredeclaredId = True
                                      Attribute VB_Exposed = True
                                      Attribute VB_TemplateDerived = False
                                      Attribute VB_Customizable = True
                                      

                                      General
                                      Stream Path:_VBA_PROJECT_CUR/VBA/Sheet3
                                      VBA File Name:Sheet3.cls
                                      Stream Size:977
                                      Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1 z < . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 2 . 0 . -
                                      Data Raw:01 16 01 00 00 f0 00 00 00 c4 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff cb 02 00 00 1f 03 00 00 00 00 00 00 01 00 00 00 31 7a c6 3c 00 00 ff ff 23 01 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                                      Attribute VB_Name = "Sheet3"
                                      Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"
                                      Attribute VB_GlobalNameSpace = False
                                      Attribute VB_Creatable = False
                                      Attribute VB_PredeclaredId = True
                                      Attribute VB_Exposed = True
                                      Attribute VB_TemplateDerived = False
                                      Attribute VB_Customizable = True
                                      

                                      General
                                      Stream Path:_VBA_PROJECT_CUR/VBA/ThisWorkbook
                                      VBA File Name:ThisWorkbook.cls
                                      Stream Size:985
                                      Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1 z . . . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 1 . 9 .
                                      Data Raw:01 16 01 00 00 f0 00 00 00 c4 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff cb 02 00 00 1f 03 00 00 00 00 00 00 01 00 00 00 31 7a 0f 0f 00 00 ff ff 23 01 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                                      Attribute VB_Name = "ThisWorkbook"
                                      Attribute VB_Base = "0{00020819-0000-0000-C000-000000000046}"
                                      Attribute VB_GlobalNameSpace = False
                                      Attribute VB_Creatable = False
                                      Attribute VB_PredeclaredId = True
                                      Attribute VB_Exposed = True
                                      Attribute VB_TemplateDerived = False
                                      Attribute VB_Customizable = True
                                      

                                      General
                                      Stream Path:\x1CompObj
                                      CLSID:
                                      File Type:data
                                      Stream Size:114
                                      Entropy:4.25248375192737
                                      Base64 Encoded:True
                                      Data ASCII:. . . . . . . . . . . . . . . . . . . F & . . . M i c r o s o f t O f f i c e E x c e l 2 0 0 3 W o r k s h e e t . . . . . B i f f 8 . . . . . E x c e l . S h e e t . 8 . 9 q . . . . . . . . . . . .
                                      Data Raw:01 00 fe ff 03 0a 00 00 ff ff ff ff 20 08 02 00 00 00 00 00 c0 00 00 00 00 00 00 46 26 00 00 00 4d 69 63 72 6f 73 6f 66 74 20 4f 66 66 69 63 65 20 45 78 63 65 6c 20 32 30 30 33 20 57 6f 72 6b 73 68 65 65 74 00 06 00 00 00 42 69 66 66 38 00 0e 00 00 00 45 78 63 65 6c 2e 53 68 65 65 74 2e 38 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00
                                      General
                                      Stream Path:\x5DocumentSummaryInformation
                                      CLSID:
                                      File Type:data
                                      Stream Size:244
                                      Entropy:2.889430592781307
                                      Base64 Encoded:False
                                      Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . + , 0 . . . . . . . . . . . . . . H . . . . . . . P . . . . . . . X . . . . . . . ` . . . . . . . h . . . . . . . p . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . S h e e t 1 . . . . . S h e e t 2 . . . . . S h e e t 3 . . . . . . . . . . . . . . . . . W o r k s h e e t s . . . . . . . . .
                                      Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 02 d5 cd d5 9c 2e 1b 10 93 97 08 00 2b 2c f9 ae 30 00 00 00 c4 00 00 00 08 00 00 00 01 00 00 00 48 00 00 00 17 00 00 00 50 00 00 00 0b 00 00 00 58 00 00 00 10 00 00 00 60 00 00 00 13 00 00 00 68 00 00 00 16 00 00 00 70 00 00 00 0d 00 00 00 78 00 00 00 0c 00 00 00 a1 00 00 00 02 00 00 00 e4 04 00 00
                                      General
                                      Stream Path:\x5SummaryInformation
                                      CLSID:
                                      File Type:data
                                      Stream Size:200
                                      Entropy:3.226575879994164
                                      Base64 Encoded:False
                                      Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . O h . . . + ' 0 . . . . . . . . . . . . . . @ . . . . . . . H . . . . . . . T . . . . . . . ` . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M i c r o s o f t E x c e l . @ . . . . | . # . @ . . . . . . . . . . . . . . .
                                      Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 e0 85 9f f2 f9 4f 68 10 ab 91 08 00 2b 27 b3 d9 30 00 00 00 98 00 00 00 07 00 00 00 01 00 00 00 40 00 00 00 04 00 00 00 48 00 00 00 08 00 00 00 54 00 00 00 12 00 00 00 60 00 00 00 0c 00 00 00 78 00 00 00 0d 00 00 00 84 00 00 00 13 00 00 00 90 00 00 00 02 00 00 00 e4 04 00 00 1e 00 00 00 04 00 00 00
                                      General
                                      Stream Path:MBD00EB272A/\x1CompObj
                                      CLSID:
                                      File Type:data
                                      Stream Size:99
                                      Entropy:3.631242196770981
                                      Base64 Encoded:False
                                      Data ASCII:. . . . . . . . . . . . . . . . . . . . . . ! . . . M i c r o s o f t O f f i c e E x c e l W o r k s h e e t . . . . . E x c e l M L 1 2 . . . . . 9 q . . . . . . . . . . . .
                                      Data Raw:01 00 fe ff 03 0a 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 21 00 00 00 4d 69 63 72 6f 73 6f 66 74 20 4f 66 66 69 63 65 20 45 78 63 65 6c 20 57 6f 72 6b 73 68 65 65 74 00 0a 00 00 00 45 78 63 65 6c 4d 4c 31 32 00 00 00 00 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00
                                      General
                                      Stream Path:MBD00EB272A/Package
                                      CLSID:
                                      File Type:Microsoft Excel 2007+
                                      Stream Size:812455
                                      Entropy:7.972532718200243
                                      Base64 Encoded:True
                                      Data ASCII:P K . . . . . . . . . . ! . . B . . . . . . . . . [ C o n t e n t _ T y p e s ] . x m l . ( . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                      Data Raw:50 4b 03 04 14 00 06 00 08 00 00 00 21 00 03 94 9d 42 d0 01 00 00 d2 07 00 00 13 00 ce 01 5b 43 6f 6e 74 65 6e 74 5f 54 79 70 65 73 5d 2e 78 6d 6c 20 a2 ca 01 28 a0 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                                      General
                                      Stream Path:MBD00EB272B/\x1Ole
                                      CLSID:
                                      File Type:data
                                      Stream Size:818
                                      Entropy:5.621553867169569
                                      Base64 Encoded:False
                                      Data ASCII:. . . . Z . D . . . . . . . . . . . . . . . . y . . . K . . . . . h . t . t . p . s . : . / . / . a . g . r . . . m . y . / . k . V . T . C . H . C . ? . & . t . h . a . n . k . s . . . l \\ % i 7 L . . 2 0 , G & K R . m s ` R a . . . H . D . . . . d % . < = . . & . } B Y B . ; ` ` I . a 2 . . / N . . y K 8 : I - * . % y H . _ 9 > ^ - } % . P ` . ' ? [ . W . p u . o . \\ . < h B o A # O . A ~ 5 . < [ C . O ` ~ . 6 a 0 < . . . . . . . . . . . . . . . . . . . C . L . 4 . 9 . F . y . T . K . p . D . U . m . q .
                                      Data Raw:01 00 00 02 8d e8 bb 5a b3 bc 1a 44 00 00 00 00 00 00 00 00 00 00 00 00 1e 01 00 00 e0 c9 ea 79 f9 ba ce 11 8c 82 00 aa 00 4b a9 0b 1a 01 00 00 68 00 74 00 74 00 70 00 73 00 3a 00 2f 00 2f 00 61 00 67 00 72 00 2e 00 6d 00 79 00 2f 00 6b 00 56 00 54 00 43 00 48 00 43 00 3f 00 26 00 74 00 68 00 61 00 6e 00 6b 00 73 00 00 00 fa 6c 5c 25 f4 69 f7 92 37 ec 4c 07 b7 db 9a 32 8b f0 e3 ac
                                      General
                                      Stream Path:Workbook
                                      CLSID:
                                      File Type:Applesoft BASIC program data, first line number 16
                                      Stream Size:410625
                                      Entropy:7.998983668897979
                                      Base64 Encoded:True
                                      Data ASCII:. . . . . . . . . . . . . . . . . / . 6 . . . . . . . * m j 4 u ( O X D b . . v ~ F . . J . . g 0 5 . . . . . . . . . . . . . . \\ . p . x ! p * . - . n | \\ y . . . ' . & b . x o _ i . k { A | e ] . . h . Y . . . | . G . 6 = C . . W . G . s ^ 5 . ? . < i . . B . . . { a . . . 5 . . . . = . . . 3 b . k O . . . Q , Q z . + . . . . l . . . . . . . . . h . . . . . . . c . . . c = . . . . M ~ . L J * $ V p @ . . . . . . . " . . . y , . . . . & . . . . . . . 1 . . . . 9 . > D O o ^ r 0 . . . . x z p . M 1 . . . q
                                      Data Raw:09 08 10 00 00 06 05 00 ab 1f cd 07 c1 00 01 00 06 04 00 00 2f 00 36 00 01 00 01 00 01 00 2a 6d d5 6a e0 34 75 28 df 4f 58 44 ed 62 d5 af 1d 8f a3 76 7e 46 e8 c0 ee b0 00 eb e6 0d 9d 4a fa 1f 0e 67 30 35 87 fe 9e ef fa 05 b6 cd c7 fb 87 00 00 00 e1 00 02 00 b0 04 c1 00 02 00 f4 ce e2 00 00 00 5c 00 70 00 ae c3 78 21 70 2a 16 b1 2d cc f6 c8 1b 9e 6e 8b 7c 5c a9 79 02 97 e1 06 1b f6
                                      General
                                      Stream Path:_VBA_PROJECT_CUR/PROJECT
                                      CLSID:
                                      File Type:ASCII text, with CRLF line terminators
                                      Stream Size:527
                                      Entropy:5.277318566589271
                                      Base64 Encoded:True
                                      Data ASCII:I D = " { 0 1 7 1 1 C 5 2 - E 6 E 5 - 4 9 F C - 8 3 A E - D E 4 A 9 E B D 1 D F 7 } " . . D o c u m e n t = T h i s W o r k b o o k / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = S h e e t 1 / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = S h e e t 2 / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = S h e e t 3 / & H 0 0 0 0 0 0 0 0 . . N a m e = " V B A P r o j e c t " . . H e l p C o n t e x t I D = " 0 " . . V e r s i o n C o m p a t i b l e 3 2 = " 3 9 3 2 2 2 0 0 0 " . . C M G = " F 8 F A D 8 1 E D C 1 E D C 1 E D
                                      Data Raw:49 44 3d 22 7b 30 31 37 31 31 43 35 32 2d 45 36 45 35 2d 34 39 46 43 2d 38 33 41 45 2d 44 45 34 41 39 45 42 44 31 44 46 37 7d 22 0d 0a 44 6f 63 75 6d 65 6e 74 3d 54 68 69 73 57 6f 72 6b 62 6f 6f 6b 2f 26 48 30 30 30 30 30 30 30 30 0d 0a 44 6f 63 75 6d 65 6e 74 3d 53 68 65 65 74 31 2f 26 48 30 30 30 30 30 30 30 30 0d 0a 44 6f 63 75 6d 65 6e 74 3d 53 68 65 65 74 32 2f 26 48 30 30 30
                                      General
                                      Stream Path:_VBA_PROJECT_CUR/PROJECTwm
                                      CLSID:
                                      File Type:data
                                      Stream Size:104
                                      Entropy:3.0488640812019017
                                      Base64 Encoded:False
                                      Data ASCII:T h i s W o r k b o o k . T . h . i . s . W . o . r . k . b . o . o . k . . . S h e e t 1 . S . h . e . e . t . 1 . . . S h e e t 2 . S . h . e . e . t . 2 . . . S h e e t 3 . S . h . e . e . t . 3 . . . . .
                                      Data Raw:54 68 69 73 57 6f 72 6b 62 6f 6f 6b 00 54 00 68 00 69 00 73 00 57 00 6f 00 72 00 6b 00 62 00 6f 00 6f 00 6b 00 00 00 53 68 65 65 74 31 00 53 00 68 00 65 00 65 00 74 00 31 00 00 00 53 68 65 65 74 32 00 53 00 68 00 65 00 65 00 74 00 32 00 00 00 53 68 65 65 74 33 00 53 00 68 00 65 00 65 00 74 00 33 00 00 00 00 00
                                      General
                                      Stream Path:_VBA_PROJECT_CUR/VBA/_VBA_PROJECT
                                      CLSID:
                                      File Type:data
                                      Stream Size:2644
                                      Entropy:3.9905096282794155
                                      Base64 Encoded:False
                                      Data ASCII:a . . . . . @ . . . . . . . . . . . . . . . . . . . . . . . . * . \\ . G . { . 0 . 0 . 0 . 2 . 0 . 4 . E . F . - . 0 . 0 . 0 . 0 . - . 0 . 0 . 0 . 0 . - . C . 0 . 0 . 0 . - . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 4 . 6 . } . # . 4 . . . 0 . # . 9 . # . C . : . \\ . P . R . O . G . R . A . ~ . 2 . \\ . C . O . M . M . O . N . ~ . 1 . \\ . M . I . C . R . O . S . ~ . 1 . \\ . V . B . A . \\ . V . B . A . 6 . \\ . V . B . E . 6 . . . D . L . L . # . V . i . s . u . a . l . . B . a . s . i . c . . F . o . r .
                                      Data Raw:cc 61 88 00 00 01 00 ff 09 40 00 00 09 04 00 00 e4 04 01 00 00 00 00 00 00 00 00 00 01 00 04 00 02 00 fa 00 2a 00 5c 00 47 00 7b 00 30 00 30 00 30 00 32 00 30 00 34 00 45 00 46 00 2d 00 30 00 30 00 30 00 30 00 2d 00 30 00 30 00 30 00 30 00 2d 00 43 00 30 00 30 00 30 00 2d 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 34 00 36 00 7d 00 23 00 34 00 2e 00 30 00 23 00
                                      General
                                      Stream Path:_VBA_PROJECT_CUR/VBA/dir
                                      CLSID:
                                      File Type:data
                                      Stream Size:553
                                      Entropy:6.372676054338537
                                      Base64 Encoded:True
                                      Data ASCII:. % . . . . . . . . 0 * . . . . p . . H . . . . d . . . . . . . V B A P r o j e c t . . 4 . . @ . . j . . . = . . . . r . . . . . . . . . 5 , i . . . . J < . . . . . r s t d o l e > . . . s . t . d . o . l . e . . . h . % . ^ . . * \\ G { 0 0 0 2 0 4 3 0 - . . . . . C . . . . . . 0 0 4 . 6 } # 2 . 0 # 0 . # C : \\ W i n d . o w s \\ S y s W O W 6 4 \\ . e 2 . . t l b # O L E . A u t o m a t i . o n . ` . . E O f f D i c E O . f . i . c E . . E . 2 D F 8 D 0 4 C . - 5 B F A - 1 0 1 B - B D E 5 E A A C 4 . 2
                                      Data Raw:01 25 b2 80 01 00 04 00 00 00 01 00 30 2a 02 02 90 09 00 70 14 06 48 03 00 82 02 00 64 e4 04 04 00 0a 00 1c 00 56 42 41 50 72 6f 6a 65 88 63 74 05 00 34 00 00 40 02 14 6a 06 02 0a 3d 02 0a 07 02 72 01 14 08 05 06 12 09 02 12 35 2c fb 69 0d 94 00 0c 02 4a 3c 02 0a 16 00 01 72 80 73 74 64 6f 6c 65 3e 02 19 00 73 00 74 00 64 00 6f 00 80 6c 00 65 00 0d 00 68 00 25 02 5e 00 03 2a 5c 47

                                      Download Network PCAP: filteredfull

                                      TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                      2025-03-26T14:08:56.593919+01002028371ET JA3 Hash - Possible Malware - Fake Firefox Font Update3192.168.2.124975913.107.246.40443TCP
                                      2025-03-26T14:09:04.312411+01002028371ET JA3 Hash - Possible Malware - Fake Firefox Font Update3192.168.2.124976013.107.246.40443TCP
                                      2025-03-26T14:09:04.327093+01002028371ET JA3 Hash - Possible Malware - Fake Firefox Font Update3192.168.2.124976113.107.246.40443TCP
                                      • Total Packets: 233
                                      • 443 (HTTPS)
                                      • 53 (DNS)
                                      TimestampSource PortDest PortSource IPDest IP
                                      Mar 26, 2025 14:08:41.321743011 CET49757443192.168.2.12147.79.86.93
                                      Mar 26, 2025 14:08:41.321804047 CET44349757147.79.86.93192.168.2.12
                                      Mar 26, 2025 14:08:41.321881056 CET49757443192.168.2.12147.79.86.93
                                      Mar 26, 2025 14:08:41.322211027 CET49757443192.168.2.12147.79.86.93
                                      Mar 26, 2025 14:08:41.322225094 CET44349757147.79.86.93192.168.2.12
                                      Mar 26, 2025 14:08:41.775887966 CET44349757147.79.86.93192.168.2.12
                                      Mar 26, 2025 14:08:41.776057005 CET49757443192.168.2.12147.79.86.93
                                      Mar 26, 2025 14:08:41.780563116 CET49757443192.168.2.12147.79.86.93
                                      Mar 26, 2025 14:08:41.780613899 CET44349757147.79.86.93192.168.2.12
                                      Mar 26, 2025 14:08:41.780972958 CET44349757147.79.86.93192.168.2.12
                                      Mar 26, 2025 14:08:41.781047106 CET49757443192.168.2.12147.79.86.93
                                      Mar 26, 2025 14:08:41.781527042 CET49757443192.168.2.12147.79.86.93
                                      Mar 26, 2025 14:08:41.824273109 CET44349757147.79.86.93192.168.2.12
                                      Mar 26, 2025 14:08:42.244370937 CET44349757147.79.86.93192.168.2.12
                                      Mar 26, 2025 14:08:42.244472027 CET44349757147.79.86.93192.168.2.12
                                      Mar 26, 2025 14:08:42.244501114 CET49757443192.168.2.12147.79.86.93
                                      Mar 26, 2025 14:08:42.244537115 CET49757443192.168.2.12147.79.86.93
                                      Mar 26, 2025 14:08:42.250432014 CET49757443192.168.2.12147.79.86.93
                                      Mar 26, 2025 14:08:42.250452042 CET44349757147.79.86.93192.168.2.12
                                      Mar 26, 2025 14:08:42.254797935 CET49758443192.168.2.12147.79.86.93
                                      Mar 26, 2025 14:08:42.254823923 CET44349758147.79.86.93192.168.2.12
                                      Mar 26, 2025 14:08:42.254893064 CET49758443192.168.2.12147.79.86.93
                                      Mar 26, 2025 14:08:42.255139112 CET49758443192.168.2.12147.79.86.93
                                      Mar 26, 2025 14:08:42.255147934 CET44349758147.79.86.93192.168.2.12
                                      Mar 26, 2025 14:08:42.696952105 CET44349758147.79.86.93192.168.2.12
                                      Mar 26, 2025 14:08:42.697246075 CET49758443192.168.2.12147.79.86.93
                                      Mar 26, 2025 14:08:42.702869892 CET49758443192.168.2.12147.79.86.93
                                      Mar 26, 2025 14:08:42.702887058 CET44349758147.79.86.93192.168.2.12
                                      Mar 26, 2025 14:08:42.703327894 CET49758443192.168.2.12147.79.86.93
                                      Mar 26, 2025 14:08:42.703335047 CET44349758147.79.86.93192.168.2.12
                                      Mar 26, 2025 14:08:43.172992945 CET44349758147.79.86.93192.168.2.12
                                      Mar 26, 2025 14:08:43.173085928 CET49758443192.168.2.12147.79.86.93
                                      Mar 26, 2025 14:08:43.173360109 CET44349758147.79.86.93192.168.2.12
                                      Mar 26, 2025 14:08:43.173418045 CET49758443192.168.2.12147.79.86.93
                                      Mar 26, 2025 14:08:43.173770905 CET44349758147.79.86.93192.168.2.12
                                      Mar 26, 2025 14:08:43.173820019 CET49758443192.168.2.12147.79.86.93
                                      Mar 26, 2025 14:08:43.173827887 CET44349758147.79.86.93192.168.2.12
                                      Mar 26, 2025 14:08:43.173862934 CET49758443192.168.2.12147.79.86.93
                                      Mar 26, 2025 14:08:43.173867941 CET44349758147.79.86.93192.168.2.12
                                      Mar 26, 2025 14:08:43.173897028 CET44349758147.79.86.93192.168.2.12
                                      Mar 26, 2025 14:08:43.173903942 CET49758443192.168.2.12147.79.86.93
                                      Mar 26, 2025 14:08:43.173934937 CET49758443192.168.2.12147.79.86.93
                                      Mar 26, 2025 14:08:43.175008059 CET49758443192.168.2.12147.79.86.93
                                      Mar 26, 2025 14:08:43.175020933 CET44349758147.79.86.93192.168.2.12
                                      Mar 26, 2025 14:08:43.175031900 CET49758443192.168.2.12147.79.86.93
                                      Mar 26, 2025 14:08:43.175062895 CET49758443192.168.2.12147.79.86.93
                                      Mar 26, 2025 14:08:56.309520960 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:56.309551954 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:56.310190916 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:56.310627937 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:56.310641050 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:56.593838930 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:56.593919039 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:56.595313072 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:56.595328093 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:56.595591068 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:56.596940994 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:56.640269041 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:56.892405987 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:56.892432928 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:56.892494917 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:56.892508984 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:56.892537117 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:56.892558098 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:56.892584085 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:56.921533108 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:56.921555996 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:56.921603918 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:56.921618938 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:56.921648026 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:56.921660900 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:56.991276026 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:56.991303921 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:56.991439104 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:56.991455078 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:56.991631985 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.008390903 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.008419037 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.008480072 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.008502960 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.008553028 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.008553028 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.035748959 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.035768032 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.036278963 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.036297083 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.036910057 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.094863892 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.094891071 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.094990015 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.094990015 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.095005989 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.095159054 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.123769999 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.123800993 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.123898983 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.123898983 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.123919010 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.124150038 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.150572062 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.150603056 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.150742054 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.150742054 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.150753021 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.150840998 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.191656113 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.191684008 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.191773891 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.191786051 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.192003965 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.192004919 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.221643925 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.221676111 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.223136902 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.223138094 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.223150015 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.224145889 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.245114088 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.245151997 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.245218992 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.245235920 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.245254993 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.246164083 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.287853956 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.287888050 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.287961006 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.287990093 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.288016081 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.288297892 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.314629078 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.314661980 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.314719915 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.314749002 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.314766884 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.318684101 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.342367887 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.342403889 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.342538118 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.342538118 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.342556000 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.342813015 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.371337891 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.371367931 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.371695042 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.371722937 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.371803999 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.401597023 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.401623964 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.401746035 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.401746035 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.401761055 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.402348995 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.429095984 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.429131031 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.429331064 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.429332018 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.429362059 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.429461002 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.454108953 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.454144001 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.454225063 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.454245090 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.454276085 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.454339027 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.487746000 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.487780094 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.487973928 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.488007069 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.488276005 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.508110046 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.508142948 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.508212090 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.508227110 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.508349895 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.508553028 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.536398888 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.536429882 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.536644936 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.536644936 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.536662102 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.536715984 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.564805031 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.564838886 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.564960003 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.564960003 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.564974070 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.565135956 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.591130018 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.591156006 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.591298103 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.591311932 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.591645956 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.614146948 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.614177942 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.614403009 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.614403963 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.614423037 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.614767075 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.636616945 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.636646032 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.636710882 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.636727095 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.636759043 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.636776924 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.664283037 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.664321899 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.664479971 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.664479971 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.664511919 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.664864063 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.689043045 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.689088106 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.689178944 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.689193964 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.689207077 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.689444065 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.710683107 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.710717916 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.711186886 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.711186886 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.711215973 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.711277008 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.735239029 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.735271931 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.735389948 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.735419989 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.735461950 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.735496998 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.757194042 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.757227898 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.758028984 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.758028984 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.758058071 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.758399010 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.780679941 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.780710936 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.780821085 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.780821085 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.780853033 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.780992985 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.806862116 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.806895018 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.807099104 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.807099104 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.807116032 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.807233095 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.819307089 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.819346905 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.819555044 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.819571972 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.819873095 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.851680040 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.851716995 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.852281094 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.852319956 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.852662086 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.982247114 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.982278109 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.982342005 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.982388973 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.982397079 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.982418060 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.982434034 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.982443094 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.982522011 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.982522011 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:57.982522964 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.982537031 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.982547998 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:57.982664108 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.008884907 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.008919954 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.009011984 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.009011984 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.009033918 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.009078979 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.032952070 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.032989025 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.033122063 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.033122063 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.033142090 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.033354044 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.061621904 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.061647892 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.061722994 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.061741114 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.061774015 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.061852932 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.100029945 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.100075006 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.100137949 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.100153923 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.100183964 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.100311995 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.129575968 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.129630089 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.129668951 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.129686117 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.129724979 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.129724979 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.166414022 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.166445971 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.166536093 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.166536093 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.166559935 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.166615009 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.180124998 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.180160046 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.180238008 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.180238008 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.180275917 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.180342913 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.220204115 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.220244884 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.220292091 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.220314026 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.220344067 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.220344067 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.256127119 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.256156921 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.256268024 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.256268024 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.256293058 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.256436110 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.279145002 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.279177904 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.279248953 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.279266119 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.279289961 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.279304981 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.306889057 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.306925058 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.306968927 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.306984901 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.307017088 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.307056904 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.330204010 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.330230951 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.330287933 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.330311060 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.330348015 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.330363035 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.362492085 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.362557888 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.362674952 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.362674952 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.362689018 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.366336107 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.386842966 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.386872053 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.386946917 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.386960983 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.386997938 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.386997938 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.414134026 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.414167881 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.414324999 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.414334059 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.414558887 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.446549892 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.446619034 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.446666002 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.446677923 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.446708918 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.446732998 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.470596075 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.470628023 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.470724106 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.470724106 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.470736027 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.470828056 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.491240978 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.491276026 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.491338015 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.491347075 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.491395950 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.491395950 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.519774914 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.519807100 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.519983053 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.519996881 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.520279884 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.552052021 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.552083969 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.552200079 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.552223921 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.552323103 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.571708918 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.571733952 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.571790934 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.571800947 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.571882963 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.600930929 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.600953102 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.601003885 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.601015091 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.601073027 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.633128881 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.633168936 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.633276939 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.633296013 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.633310080 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.633548021 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.657716990 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.657752991 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.657917976 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.657917976 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.657941103 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.658042908 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.674983025 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.675014019 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.675085068 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.675103903 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.675144911 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.675144911 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.706065893 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.706094980 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.706198931 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.706218004 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.706267118 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.706267118 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.736108065 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.736131907 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.736223936 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.736223936 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.736238956 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.736725092 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.762414932 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.762444973 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.762557983 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.762574911 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.762840986 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.786449909 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.786478043 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.786513090 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.786566973 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.786566973 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.786578894 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.786591053 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.786709070 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.786792994 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.786813974 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:08:58.786823034 CET49759443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:08:58.786828041 CET4434975913.107.246.40192.168.2.12
                                      Mar 26, 2025 14:09:04.024874926 CET49761443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:09:04.024924040 CET4434976113.107.246.40192.168.2.12
                                      Mar 26, 2025 14:09:04.024981022 CET49760443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:09:04.024998903 CET4434976013.107.246.40192.168.2.12
                                      Mar 26, 2025 14:09:04.025039911 CET49761443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:09:04.025280952 CET49760443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:09:04.027806997 CET49761443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:09:04.027817965 CET4434976113.107.246.40192.168.2.12
                                      Mar 26, 2025 14:09:04.028040886 CET49760443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:09:04.028050900 CET4434976013.107.246.40192.168.2.12
                                      Mar 26, 2025 14:09:04.305918932 CET4434976013.107.246.40192.168.2.12
                                      Mar 26, 2025 14:09:04.306071043 CET4434976113.107.246.40192.168.2.12
                                      Mar 26, 2025 14:09:04.312411070 CET49760443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:09:04.312436104 CET4434976013.107.246.40192.168.2.12
                                      Mar 26, 2025 14:09:04.326355934 CET49760443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:09:04.326366901 CET4434976013.107.246.40192.168.2.12
                                      Mar 26, 2025 14:09:04.327092886 CET49761443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:09:04.327119112 CET4434976113.107.246.40192.168.2.12
                                      Mar 26, 2025 14:09:04.347237110 CET49761443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:09:04.347265959 CET4434976113.107.246.40192.168.2.12
                                      Mar 26, 2025 14:09:04.488301992 CET4434976013.107.246.40192.168.2.12
                                      Mar 26, 2025 14:09:04.488331079 CET4434976013.107.246.40192.168.2.12
                                      Mar 26, 2025 14:09:04.488486052 CET49760443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:09:04.488502979 CET4434976013.107.246.40192.168.2.12
                                      Mar 26, 2025 14:09:04.488630056 CET4434976013.107.246.40192.168.2.12
                                      Mar 26, 2025 14:09:04.488785028 CET49760443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:09:04.488796949 CET4434976113.107.246.40192.168.2.12
                                      Mar 26, 2025 14:09:04.489346981 CET4434976113.107.246.40192.168.2.12
                                      Mar 26, 2025 14:09:04.492270947 CET49760443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:09:04.492290020 CET4434976013.107.246.40192.168.2.12
                                      Mar 26, 2025 14:09:04.492537975 CET49761443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:09:04.522165060 CET49761443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:09:04.522165060 CET49761443192.168.2.1213.107.246.40
                                      Mar 26, 2025 14:09:04.522208929 CET4434976113.107.246.40192.168.2.12
                                      Mar 26, 2025 14:09:04.522222042 CET4434976113.107.246.40192.168.2.12
                                      TimestampSource PortDest PortSource IPDest IP
                                      Mar 26, 2025 14:07:28.201853991 CET5648753192.168.2.121.1.1.1
                                      Mar 26, 2025 14:07:28.299495935 CET53564871.1.1.1192.168.2.12
                                      Mar 26, 2025 14:08:41.207173109 CET5333753192.168.2.121.1.1.1
                                      Mar 26, 2025 14:08:41.320658922 CET53533371.1.1.1192.168.2.12
                                      Mar 26, 2025 14:08:56.188347101 CET6413753192.168.2.121.1.1.1
                                      Mar 26, 2025 14:08:56.308496952 CET53641371.1.1.1192.168.2.12
                                      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                      Mar 26, 2025 14:07:28.201853991 CET192.168.2.121.1.1.10x7e4eStandard query (0)otelrules.svc.static.microsoftA (IP address)IN (0x0001)false
                                      Mar 26, 2025 14:08:41.207173109 CET192.168.2.121.1.1.10xce95Standard query (0)agr.myA (IP address)IN (0x0001)false
                                      Mar 26, 2025 14:08:56.188347101 CET192.168.2.121.1.1.10xcea1Standard query (0)otelrules.svc.static.microsoftA (IP address)IN (0x0001)false
                                      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                      Mar 26, 2025 14:07:28.299495935 CET1.1.1.1192.168.2.120x7e4eNo error (0)otelrules.svc.static.microsoftotelrules-bzhndjfje8dvh5fd.z01.azurefd.netCNAME (Canonical name)IN (0x0001)false
                                      Mar 26, 2025 14:07:28.299495935 CET1.1.1.1192.168.2.120x7e4eNo error (0)otelrules-bzhndjfje8dvh5fd.z01.azurefd.netstar-azurefd-prod.trafficmanager.netCNAME (Canonical name)IN (0x0001)false
                                      Mar 26, 2025 14:07:28.299495935 CET1.1.1.1192.168.2.120x7e4eNo error (0)star-azurefd-prod.trafficmanager.netshed.dual-low.s-part-0010.t-0009.t-msedge.netCNAME (Canonical name)IN (0x0001)false
                                      Mar 26, 2025 14:07:28.299495935 CET1.1.1.1192.168.2.120x7e4eNo error (0)shed.dual-low.s-part-0010.t-0009.t-msedge.nets-part-0010.t-0009.t-msedge.netCNAME (Canonical name)IN (0x0001)false
                                      Mar 26, 2025 14:07:28.299495935 CET1.1.1.1192.168.2.120x7e4eNo error (0)s-part-0010.t-0009.t-msedge.net13.107.246.38A (IP address)IN (0x0001)false
                                      Mar 26, 2025 14:07:52.019475937 CET1.1.1.1192.168.2.120xc1e4No error (0)ecs-office.s-0005.dual-s-msedge.nets-0005.dual-s-msedge.netCNAME (Canonical name)IN (0x0001)false
                                      Mar 26, 2025 14:07:52.019475937 CET1.1.1.1192.168.2.120xc1e4No error (0)s-0005.dual-s-msedge.net52.123.128.14A (IP address)IN (0x0001)false
                                      Mar 26, 2025 14:07:52.019475937 CET1.1.1.1192.168.2.120xc1e4No error (0)s-0005.dual-s-msedge.net52.123.129.14A (IP address)IN (0x0001)false
                                      Mar 26, 2025 14:08:41.320658922 CET1.1.1.1192.168.2.120xce95No error (0)agr.my147.79.86.93A (IP address)IN (0x0001)false
                                      Mar 26, 2025 14:08:56.308496952 CET1.1.1.1192.168.2.120xcea1No error (0)otelrules.svc.static.microsoftotelrules-bzhndjfje8dvh5fd.z01.azurefd.netCNAME (Canonical name)IN (0x0001)false
                                      Mar 26, 2025 14:08:56.308496952 CET1.1.1.1192.168.2.120xcea1No error (0)otelrules-bzhndjfje8dvh5fd.z01.azurefd.netstar-azurefd-prod.trafficmanager.netCNAME (Canonical name)IN (0x0001)false
                                      Mar 26, 2025 14:08:56.308496952 CET1.1.1.1192.168.2.120xcea1No error (0)star-azurefd-prod.trafficmanager.netshed.dual-low.s-part-0012.t-0009.t-msedge.netCNAME (Canonical name)IN (0x0001)false
                                      Mar 26, 2025 14:08:56.308496952 CET1.1.1.1192.168.2.120xcea1No error (0)shed.dual-low.s-part-0012.t-0009.t-msedge.nets-part-0012.t-0009.t-msedge.netCNAME (Canonical name)IN (0x0001)false
                                      Mar 26, 2025 14:08:56.308496952 CET1.1.1.1192.168.2.120xcea1No error (0)s-part-0012.t-0009.t-msedge.net13.107.246.40A (IP address)IN (0x0001)false
                                      • agr.my
                                      • otelrules.svc.static.microsoft
                                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                      0192.168.2.1249757147.79.86.934436192C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                                      TimestampBytes transferredDirectionData
                                      2025-03-26 13:08:41 UTC198OUTGET /kVTCHC?&thanks HTTP/1.1
                                      Accept: */*
                                      Accept-Encoding: gzip, deflate
                                      User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like Gecko
                                      Host: agr.my
                                      Connection: Keep-Alive
                                      2025-03-26 13:08:42 UTC397INHTTP/1.1 301 Moved Permanently
                                      Content-Length: 38
                                      Content-Type: text/plain; charset=utf-8
                                      Date: Wed, 26 Mar 2025 13:08:42 GMT
                                      Location: /404
                                      Strict-Transport-Security: max-age=15552000; includeSubDomains
                                      Vary: Accept
                                      X-Content-Type-Options: nosniff
                                      X-Dns-Prefetch-Control: off
                                      X-Download-Options: noopen
                                      X-Frame-Options: SAMEORIGIN
                                      X-Xss-Protection: 1; mode=block
                                      Connection: close
                                      2025-03-26 13:08:42 UTC38INData Raw: 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 2e 20 52 65 64 69 72 65 63 74 69 6e 67 20 74 6f 20 2f 34 30 34
                                      Data Ascii: Moved Permanently. Redirecting to /404


                                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                      1192.168.2.1249758147.79.86.934436192C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                                      TimestampBytes transferredDirectionData
                                      2025-03-26 13:08:42 UTC187OUTGET /404 HTTP/1.1
                                      Accept: */*
                                      Accept-Encoding: gzip, deflate
                                      User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like Gecko
                                      Host: agr.my
                                      Connection: Keep-Alive
                                      2025-03-26 13:08:43 UTC454INHTTP/1.1 404 Not Found
                                      Content-Type: text/html; charset=utf-8
                                      Date: Wed, 26 Mar 2025 13:08:43 GMT
                                      Etag: "1225-4lR+8o8+z0M1Iq6OMuNgxAtPjT8"
                                      Strict-Transport-Security: max-age=15552000; includeSubDomains
                                      Vary: Accept-Encoding
                                      X-Content-Type-Options: nosniff
                                      X-Dns-Prefetch-Control: off
                                      X-Download-Options: noopen
                                      X-Frame-Options: SAMEORIGIN
                                      X-Powered-By: Next.js
                                      X-Xss-Protection: 1; mode=block
                                      Connection: close
                                      Transfer-Encoding: chunked
                                      2025-03-26 13:08:43 UTC2372INData Raw: 31 32 32 35 0d 0a 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 3c 68 74 6d 6c 20 6c 61 6e 67 3d 22 65 6e 22 3e 3c 68 65 61 64 3e 3c 6d 65 74 61 20 63 68 61 72 53 65 74 3d 22 75 74 66 2d 38 22 2f 3e 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2c 20 76 69 65 77 70 6f 72 74 2d 66 69 74 3d 63 6f 76 65 72 22 2f 3e 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 64 65 73 63 72 69 70 74 69 6f 6e 22 20 63 6f 6e 74 65 6e 74 3d 22 75 6e 64 65 66 69 6e 65 64 20 69 73 20 61 20 66 72 65 65 20 61 6e 64 20 6f 70 65 6e 20 73 6f 75 72 63 65 20 55 52 4c 20 73 68 6f 72 74 65 6e 65 72 20 77 69 74 68 20 63 75 73 74 6f 6d 20 64 6f 6d 61
                                      Data Ascii: 1225<!DOCTYPE html><html lang="en"><head><meta charSet="utf-8"/><meta name="viewport" content="width=device-width, initial-scale=1, viewport-fit=cover"/><meta name="description" content="undefined is a free and open source URL shortener with custom doma
                                      2025-03-26 13:08:43 UTC1724INData Raw: 67 69 6e 3a 30 3b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 68 73 6c 28 32 30 36 2c 20 31 32 25 2c 20 39 35 25 29 3b 66 6f 6e 74 3a 31 36 70 78 2f 31 2e 34 35 20 26 71 75 6f 74 3b 4e 75 6e 69 74 6f 26 71 75 6f 74 3b 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 6f 76 65 72 66 6c 6f 77 2d 78 3a 68 69 64 64 65 6e 3b 63 6f 6c 6f 72 3a 68 73 6c 28 32 30 30 2c 20 33 35 25 2c 20 32 35 25 29 22 3e 3c 64 69 76 20 69 64 3d 22 5f 5f 6e 65 78 74 22 3e 3c 64 69 76 20 73 74 79 6c 65 3d 22 63 6f 6c 6f 72 3a 23 30 30 30 3b 62 61 63 6b 67 72 6f 75 6e 64 3a 23 66 66 66 3b 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 2d 61 70 70 6c 65 2d 73 79 73 74 65 6d 2c 20 42 6c 69 6e 6b 4d 61 63 53 79 73 74 65 6d 46 6f 6e 74 2c 20 52 6f 62 6f 74 6f 2c 20 26 71 75 6f 74 3b 53 65 67 6f 65 20
                                      Data Ascii: gin:0;background-color:hsl(206, 12%, 95%);font:16px/1.45 &quot;Nunito&quot;, sans-serif;overflow-x:hidden;color:hsl(200, 35%, 25%)"><div id="__next"><div style="color:#000;background:#fff;font-family:-apple-system, BlinkMacSystemFont, Roboto, &quot;Segoe
                                      2025-03-26 13:08:43 UTC557INData Raw: 63 72 69 70 74 20 73 72 63 3d 22 2f 5f 6e 65 78 74 2f 73 74 61 74 69 63 2f 63 68 75 6e 6b 73 2f 66 72 61 6d 65 77 6f 72 6b 2e 62 32 65 63 33 32 36 37 31 37 37 33 66 65 32 33 33 33 63 30 2e 6a 73 22 20 61 73 79 6e 63 3d 22 22 3e 3c 2f 73 63 72 69 70 74 3e 3c 73 63 72 69 70 74 20 73 72 63 3d 22 2f 5f 6e 65 78 74 2f 73 74 61 74 69 63 2f 63 68 75 6e 6b 73 2f 63 6f 6d 6d 6f 6e 73 2e 63 66 31 62 65 33 31 34 65 62 31 35 65 30 62 38 61 66 64 63 2e 6a 73 22 20 61 73 79 6e 63 3d 22 22 3e 3c 2f 73 63 72 69 70 74 3e 3c 73 63 72 69 70 74 20 73 72 63 3d 22 2f 5f 6e 65 78 74 2f 73 74 61 74 69 63 2f 63 68 75 6e 6b 73 2f 38 36 38 64 32 62 37 36 34 33 61 66 62 33 38 61 63 33 34 65 37 33 32 38 35 31 36 38 31 34 39 32 66 32 63 64 32 35 34 30 2e 37 64 37 61 32 30 61 37 30 30
                                      Data Ascii: cript src="/_next/static/chunks/framework.b2ec32671773fe2333c0.js" async=""></script><script src="/_next/static/chunks/commons.cf1be314eb15e0b8afdc.js" async=""></script><script src="/_next/static/chunks/868d2b7643afb38ac34e732851681492f2cd2540.7d7a20a700
                                      2025-03-26 13:08:43 UTC5INData Raw: 30 0d 0a 0d 0a
                                      Data Ascii: 0


                                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                      2192.168.2.124975913.107.246.404436192C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                                      TimestampBytes transferredDirectionData
                                      2025-03-26 13:08:56 UTC226OUTGET /rules/excel.exe-Production-v19.bundle HTTP/1.1
                                      Connection: Keep-Alive
                                      Accept-Encoding: gzip
                                      User-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Excel 16.0.16827; Pro)
                                      Host: otelrules.svc.static.microsoft
                                      2025-03-26 13:08:56 UTC472INHTTP/1.1 200 OK
                                      Date: Wed, 26 Mar 2025 13:08:56 GMT
                                      Content-Type: text/plain
                                      Content-Length: 1114783
                                      Connection: close
                                      Vary: Accept-Encoding
                                      Cache-Control: public
                                      Last-Modified: Mon, 24 Mar 2025 13:40:54 GMT
                                      ETag: "0x8DD6AD97FEF19EF"
                                      x-ms-request-id: ebdb26f1-701e-000d-2b05-9e6de3000000
                                      x-ms-version: 2018-03-28
                                      x-azure-ref: 20250326T130856Z-17cccd5449bqnwr7hC1EWRa6600000000gvg000000000hv4
                                      x-fd-int-roxy-purgeid: 0
                                      X-Cache: TCP_HIT
                                      Accept-Ranges: bytes
                                      2025-03-26 13:08:56 UTC15912INData Raw: 31 30 30 30 34 32 76 32 2b 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 30 30 30 34 32 22 20 56 3d 22 32 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 55 58 2e 44 65 73 6b 74 6f 70 2e 4f 66 66 69 63 65 54 68 65 6d 65 2e 41 70 70 2e 49 6e 69 74 22 20 41 54 54 3d 22 63 34 33 38 38 63 39 37 37 32 39 37 34 31 33 62 62 30 35 34 62 61 64 31 61 63 66 30 61 64 65 31 2d 63 63 35 38 65 35 33 65 2d 66 35 61 34 2d 34 66 33 37 2d 62 30 64 32 2d 39 61 38 30 37 39 65 33 34 34 32 30 2d 36 38 37 39 22 20 44 43 61 3d 22 50 53 55 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 54 53 20 54 3d 22 31 22 20 49 64 3d 22 63 6d 39 79 35
                                      Data Ascii: 100042v2+<?xml version="1.0" encoding="utf-8"?><R Id="100042" V="2" DC="SM" EN="Office.UX.Desktop.OfficeTheme.App.Init" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" DCa="PSU" xmlns=""> <S> <UTS T="1" Id="cm9y5
                                      2025-03-26 13:08:56 UTC16384INData Raw: 21 23 3e 31 30 30 31 31 37 76 30 2b 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 30 30 31 31 37 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 44 43 61 3d 22 50 53 55 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 54 53 20 54 3d 22 31 22 20 49 64 3d 22 38 79 6c 6c 66 22 20 2f 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 66 61 6c 73 65 22 3e 0d 0a 20 20 20 20 3c 56 20 56 3d 22 43 6c 69 63 6b 22 20 54 3d 22 57 22 20 2f 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 31 22 20 4f 3d 22 66 61 6c 73 65 22 3e 0d 0a 20
                                      Data Ascii: !#>100117v0+<?xml version="1.0" encoding="utf-8"?><R Id="100117" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns=""> <S> <UTS T="1" Id="8yllf" /> </S> <C T="W" I="0" O="false"> <V V="Click" T="W" /> </C> <C T="U32" I="1" O="false">
                                      2025-03-26 13:08:56 UTC16384INData Raw: 3c 53 20 54 3d 22 32 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 20 54 3d 22 33 22 20 2f 3e 0d 0a 20 20 3c 2f 54 3e 0d 0a 3c 2f 52 3e 0d 0a 3c 24 21 23 3e 31 30 37 38 31 76 31 2b 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 30 37 38 31 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 54 53 20 54 3d 22 31 22 20 49 64 3d 22 62 67 6f 34 74 22 20 2f 3e 0d 0a 20 20 20 20 3c 55 54 53 20 54 3d 22 32 22 20 49 64 3d 22 62 68 6c 76 79 22 20 2f 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 49 33 32 22 20 49 3d 22 30 22 20 4f 3d 22 66 61 6c 73 65 22 3e 0d 0a 20
                                      Data Ascii: <S T="2" /> <S T="3" /> </T></R><$!#>10781v1+<?xml version="1.0" encoding="utf-8"?><R Id="10781" V="1" DC="SM" T="Subrule" xmlns=""> <S> <UTS T="1" Id="bgo4t" /> <UTS T="2" Id="bhlvy" /> </S> <C T="I32" I="0" O="false">
                                      2025-03-26 13:08:57 UTC16384INData Raw: 20 20 20 3c 4f 20 54 3d 22 47 54 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 56 20 56 3d 22 31 30 30 30 22 20 54 3d 22 55 33 32 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 4f 20 54 3d 22 4c 45 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20
                                      Data Ascii: <O T="GT"> <L> <S T="1" F="0" /> </L> <R> <V V="1000" T="U32" /> </R> </O> </L> <R> <O T="LE"> <L> <S
                                      2025-03-26 13:08:57 UTC16384INData Raw: 46 6c 79 6f 75 74 56 69 64 65 6f 43 61 6c 6c 56 69 64 65 6f 22 3e 0d 0a 20 20 20 20 3c 43 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 32 36 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 43 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 32 33 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 46 6c 79 6f 75 74 53 61 53 22 3e 0d 0a 20 20 20 20 3c 43 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 32 37 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 43 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 32 34 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 46 6c 79 6f 75 74 4f 76 65 72 66 6c 6f 77 22 3e 0d 0a 20 20 20 20 3c 43 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 32 38 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 43 3e 0d 0a 20
                                      Data Ascii: FlyoutVideoCallVideo"> <C> <S T="26" /> </C> </C> <C T="U32" I="23" O="false" N="FlyoutSaS"> <C> <S T="27" /> </C> </C> <C T="U32" I="24" O="false" N="FlyoutOverflow"> <C> <S T="28" /> </C>
                                      2025-03-26 13:08:57 UTC16384INData Raw: 49 64 3d 22 31 30 39 30 37 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 4f 75 74 6c 6f 6f 6b 2e 44 65 73 6b 74 6f 70 2e 4e 44 42 2e 55 6e 6b 6e 6f 77 6e 2e 43 6f 72 72 75 70 74 69 6f 6e 22 20 41 54 54 3d 22 64 38 30 37 36 30 39 32 37 36 37 34 34 32 34 35 62 61 66 38 31 62 66 37 62 63 38 30 33 33 66 36 2d 32 32 36 38 65 33 37 34 2d 37 37 36 36 2d 34 39 37 36 2d 62 65 34 34 2d 62 36 61 64 35 62 64 64 63 35 62 36 2d 37 38 31 33 22 20 53 3d 22 31 30 30 22 20 44 43 61 3d 22 50 53 55 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 45 74 77 20 54 3d 22 31 22 20 45 3d 22 33 39 35 22 20 47 3d 22 7b 32 61 64 66 38 65 32 33 2d 30 61 66 39 2d 34 33 63 39 2d 62 61 34 63 2d 39 35 32 65 65 31 33 30 35 34 30
                                      Data Ascii: Id="10907" V="0" DC="SM" EN="Office.Outlook.Desktop.NDB.Unknown.Corruption" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSU" xmlns=""> <S> <Etw T="1" E="395" G="{2adf8e23-0af9-43c9-ba4c-952ee130540
                                      2025-03-26 13:08:57 UTC16384INData Raw: 3e 0d 0a 20 20 20 20 3c 55 54 53 20 54 3d 22 33 22 20 49 64 3d 22 62 70 66 79 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 34 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 47 54 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 33 22 20 46 3d 22 50 68 6f 74 6f 53 69 7a 65 49 6e 42 79 74 65 73 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 56 20 56 3d 22 30 22 20 54 3d 22 55 36 34 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 20 20 3c 2f 46 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 36 34 22 20 49 3d 22 30 22 20 4f 3d 22 74 72 75 65 22 20 4e 3d
                                      Data Ascii: > <UTS T="3" Id="bpfy1" /> <F T="4"> <O T="GT"> <L> <S T="3" F="PhotoSizeInBytes" /> </L> <R> <V V="0" T="U64" /> </R> </O> </F> </S> <C T="U64" I="0" O="true" N=
                                      2025-03-26 13:08:57 UTC16384INData Raw: 22 34 22 20 46 3d 22 65 76 65 6e 74 49 64 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 56 20 56 3d 22 31 33 35 22 20 54 3d 22 49 33 32 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 20 20 3c 2f 46 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 37 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 35 22 20 46 3d 22 74 63 69 64 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 56 20 56 3d 22 32 37 38 35 32 22 20 54 3d 22 49 33 32 22 20 2f 3e 0d
                                      Data Ascii: "4" F="eventId" /> </L> <R> <V V="135" T="I32" /> </R> </O> </F> <F T="7"> <O T="EQ"> <L> <S T="5" F="tcid" /> </L> <R> <V V="27852" T="I32" />
                                      2025-03-26 13:08:57 UTC16384INData Raw: 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 33 22 20 46 3d 22 46 69 6c 65 50 72 6f 74 65 63 74 69 6f 6e 53 74 61 74 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 56 20 56 3d 22 35 22 20 54 3d 22 55 33 32 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 20 20 3c 2f 46 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 30 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 43 6f 75 6e 74 4f 66 54 68 72 6f 77 6e 45 78 63 65 70 74 69 6f 6e 22 3e 0d 0a 20 20 20 20 3c 43 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d
                                      Data Ascii: <O T="EQ"> <L> <S T="3" F="FileProtectionState" /> </L> <R> <V V="5" T="U32" /> </R> </O> </F> </S> <C T="U32" I="0" O="false" N="CountOfThrownException"> <C> <S T=
                                      2025-03-26 13:08:57 UTC16384INData Raw: 3d 22 72 65 73 75 6c 74 73 5f 49 73 4e 75 6c 6c 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 56 20 56 3d 22 66 61 6c 73 65 22 20 54 3d 22 42 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 35
                                      Data Ascii: ="results_IsNull" /> </L> <R> <V V="false" T="B" /> </R> </O> </L> <R> <O T="EQ"> <L> <S T="5


                                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                      3192.168.2.124976013.107.246.404436192C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                                      TimestampBytes transferredDirectionData
                                      2025-03-26 13:09:04 UTC214OUTGET /rules/rule120603v8s19.xml HTTP/1.1
                                      Connection: Keep-Alive
                                      Accept-Encoding: gzip
                                      User-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Excel 16.0.16827; Pro)
                                      Host: otelrules.svc.static.microsoft
                                      2025-03-26 13:09:04 UTC494INHTTP/1.1 200 OK
                                      Date: Wed, 26 Mar 2025 13:09:04 GMT
                                      Content-Type: text/xml
                                      Content-Length: 2128
                                      Connection: close
                                      Vary: Accept-Encoding
                                      Cache-Control: public, max-age=604800, immutable
                                      Last-Modified: Tue, 09 Apr 2024 00:26:04 GMT
                                      ETag: "0x8DC582BA41F3C62"
                                      x-ms-request-id: 0fe88ecf-101e-007a-32da-9b047e000000
                                      x-ms-version: 2018-03-28
                                      x-azure-ref: 20250326T130904Z-17cccd5449bcdqb4hC1EWRt7pn00000006gg000000008wy0
                                      x-fd-int-roxy-purgeid: 0
                                      X-Cache: TCP_HIT
                                      Accept-Ranges: bytes
                                      2025-03-26 13:09:04 UTC2128INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 30 33 22 20 56 3d 22 38 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 53 79 73 74 65 6d 2e 53 79 73 74 65 6d 48 65 61 6c 74 68 4d 65 74 61 64 61 74 61 41 70 70 6c 69 63 61 74 69 6f 6e 41 64 64 69 74 69 6f 6e 61 6c 22 20 41 54 54 3d 22 63 64 38 33 36 36 32 36 36 31 31 63 34 63 61 61 61 38 66 63 35 62 32 65 37 32 38 65 65 38 31 64 2d 33 62 36 64 36 63 34 35 2d 36 33 37 37 2d 34 62 66 35 2d 39 37 39 32 2d 64 62 66 38 65 31 38 38 31 30 38 38 2d 37 35 32 31 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 45 3d 22 66 61 6c 73 65 22 20 44 4c 3d
                                      Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120603" V="8" DC="SM" EN="Office.System.SystemHealthMetadataApplicationAdditional" ATT="cd836626611c4caaa8fc5b2e728ee81d-3b6d6c45-6377-4bf5-9792-dbf8e1881088-7521" SP="CriticuserinessImpact" E="false" DL=


                                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                      4192.168.2.124976113.107.246.404436192C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                                      TimestampBytes transferredDirectionData
                                      2025-03-26 13:09:04 UTC214OUTGET /rules/rule120607v1s19.xml HTTP/1.1
                                      Connection: Keep-Alive
                                      Accept-Encoding: gzip
                                      User-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Excel 16.0.16827; Pro)
                                      Host: otelrules.svc.static.microsoft
                                      2025-03-26 13:09:04 UTC470INHTTP/1.1 200 OK
                                      Date: Wed, 26 Mar 2025 13:09:04 GMT
                                      Content-Type: text/xml
                                      Content-Length: 204
                                      Connection: close
                                      Cache-Control: public, max-age=604800, immutable
                                      Last-Modified: Tue, 09 Apr 2024 00:26:35 GMT
                                      ETag: "0x8DC582BB6C8527A"
                                      x-ms-request-id: fe09a350-901e-0048-3adf-9cb800000000
                                      x-ms-version: 2018-03-28
                                      x-azure-ref: 20250326T130904Z-17cccd5449bgvc9thC1EWR7dt00000000gtg0000000087h0
                                      x-fd-int-roxy-purgeid: 0
                                      X-Cache: TCP_HIT
                                      Accept-Ranges: bytes
                                      2025-03-26 13:09:04 UTC204INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 30 37 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 45 52 3d 22 31 32 30 36 30 33 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 54 53 20 54 3d 22 31 22 20 49 64 3d 22 62 62 70 7a 73 22 20 41 3d 22 39 34 30 74 63 20 39 78 35 6a 73 22 20 2f 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 54 3e 0d 0a 20 20 20 20 3c 53 20 54 3d 22 31 22 20 2f 3e 0d 0a 20 20 3c 2f 54 3e 0d 0a 3c 2f 52 3e
                                      Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120607" V="1" DC="SM" T="Subrule" ER="120603" xmlns=""> <S> <UTS T="1" Id="bbpzs" A="940tc 9x5js" /> </S> <T> <S T="1" /> </T></R>


                                      050100s020406080100

                                      Click to jump to process

                                      050100s0.0050100150MB

                                      Click to jump to process

                                      • File
                                      • Registry

                                      Click to dive into process behavior distribution

                                      Target ID:0
                                      Start time:09:07:46
                                      Start date:26/03/2025
                                      Path:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                                      Wow64 process (32bit):true
                                      Commandline:"C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" /automation -Embedding
                                      Imagebase:0xee0000
                                      File size:53'161'064 bytes
                                      MD5 hash:4A871771235598812032C822E6F68F19
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Reputation:high
                                      Has exited:false
                                      There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                                      There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                                      There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                                      There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

                                      Target ID:6
                                      Start time:09:08:50
                                      Start date:26/03/2025
                                      Path:C:\Windows\splwow64.exe
                                      Wow64 process (32bit):false
                                      Commandline:C:\Windows\splwow64.exe 12288
                                      Imagebase:0x7ff76ed70000
                                      File size:163'840 bytes
                                      MD5 hash:77DE7761B037061C7C112FD3C5B91E73
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Reputation:high
                                      Has exited:false
                                      There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                                      There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                                      There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                                      There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                                      There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                                      There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                                      There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

                                      Target ID:9
                                      Start time:09:09:00
                                      Start date:26/03/2025
                                      Path:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                                      Wow64 process (32bit):true
                                      Commandline:"C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" "C:\Users\user\Desktop\ORDER 517-2025.xla.xlsx"
                                      Imagebase:0xee0000
                                      File size:53'161'064 bytes
                                      MD5 hash:4A871771235598812032C822E6F68F19
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Reputation:high
                                      Has exited:true
                                      There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                                      There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                                      There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                                      There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

                                      Call Graph

                                      Hide Legend
                                      • Entrypoint
                                      • Decryption Function
                                      • Executed
                                      • Not Executed
                                      • Show Help
                                      callgraph 1 Error: Graph is empty

                                      Module: Sheet1

                                      Declaration
                                      LineContent
                                      1

                                      Attribute VB_Name = "Sheet1"

                                      2

                                      Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"

                                      3

                                      Attribute VB_GlobalNameSpace = False

                                      4

                                      Attribute VB_Creatable = False

                                      5

                                      Attribute VB_PredeclaredId = True

                                      6

                                      Attribute VB_Exposed = True

                                      7

                                      Attribute VB_TemplateDerived = False

                                      8

                                      Attribute VB_Customizable = True

                                      Module: Sheet2

                                      Declaration
                                      LineContent
                                      1

                                      Attribute VB_Name = "Sheet2"

                                      2

                                      Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"

                                      3

                                      Attribute VB_GlobalNameSpace = False

                                      4

                                      Attribute VB_Creatable = False

                                      5

                                      Attribute VB_PredeclaredId = True

                                      6

                                      Attribute VB_Exposed = True

                                      7

                                      Attribute VB_TemplateDerived = False

                                      8

                                      Attribute VB_Customizable = True

                                      Module: Sheet3

                                      Declaration
                                      LineContent
                                      1

                                      Attribute VB_Name = "Sheet3"

                                      2

                                      Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"

                                      3

                                      Attribute VB_GlobalNameSpace = False

                                      4

                                      Attribute VB_Creatable = False

                                      5

                                      Attribute VB_PredeclaredId = True

                                      6

                                      Attribute VB_Exposed = True

                                      7

                                      Attribute VB_TemplateDerived = False

                                      8

                                      Attribute VB_Customizable = True

                                      Module: ThisWorkbook

                                      Declaration
                                      LineContent
                                      1

                                      Attribute VB_Name = "ThisWorkbook"

                                      2

                                      Attribute VB_Base = "0{00020819-0000-0000-C000-000000000046}"

                                      3

                                      Attribute VB_GlobalNameSpace = False

                                      4

                                      Attribute VB_Creatable = False

                                      5

                                      Attribute VB_PredeclaredId = True

                                      6

                                      Attribute VB_Exposed = True

                                      7

                                      Attribute VB_TemplateDerived = False

                                      8

                                      Attribute VB_Customizable = True