Windows
Analysis Report
FFL-2025-00947 PAYMENT.docx.doc
Overview
General Information
Detection
Score: | 60 |
Range: | 0 - 100 |
Confidence: | 100% |
Signatures
Classification
- System is w11x64_office
WINWORD.EXE (PID: 7056 cmdline:
"C:\Progra m Files\Mi crosoft Of fice\Root\ Office16\W INWORD.EXE " /Automat ion -Embed ding MD5: A9F0EC89897AC6C878D217DFB64CA752)
- cleanup
Source: | Author: X__Junior (Nextron Systems): |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-04-18T06:56:12.160852+0200 | 1810004 | 1 | Potentially Bad Traffic | 192.168.2.24 | 60832 | 104.21.20.196 | 443 | TCP |
2025-04-18T06:56:12.681332+0200 | 1810004 | 1 | Potentially Bad Traffic | 192.168.2.24 | 60834 | 203.202.232.170 | 80 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-04-18T06:56:09.820739+0200 | 1810005 | 1 | Potentially Bad Traffic | 192.168.2.24 | 60828 | 104.21.20.196 | 443 | TCP |
- • AV Detection
- • Compliance
- • Software Vulnerabilities
- • Networking
- • System Summary
- • Persistence and Installation Behavior
- • Hooking and other Techniques for Hiding and Protection
- • Malware Analysis System Evasion
Click to jump to signature section
AV Detection |
---|
Source: | Virustotal: | Perma Link | ||
Source: | ReversingLabs: |
Source: | File opened: | Jump to behavior |
Source: | HTTPS traffic detected: |
Source: | DNS query: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | Memory has grown: |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | IP Address: | ||
Source: | IP Address: |
Source: | ASN Name: |
Source: | JA3 fingerprint: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | OLE indicator, Word Document stream: |
Source: | OLE document summary: | ||
Source: | OLE document summary: |
Source: | WMI Queries: |
Source: | File read: | Jump to behavior |
Source: | Virustotal: | ||
Source: | ReversingLabs: |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Source: | Initial sample: | ||
Source: | Initial sample: |
Source: | Key opened: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Initial sample: |
Source: | Initial sample: |
Persistence and Installation Behavior |
---|
Source: | Extracted files from sample: |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Source: | WMI Queries: |
Source: | Process information queried: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 11 Windows Management Instrumentation | Path Interception | 1 Process Injection | 1 Masquerading | OS Credential Dumping | 1 Security Software Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 3 Exploitation for Client Execution | Boot or Logon Initialization Scripts | 1 Extra Window Memory Injection | 1 Virtualization/Sandbox Evasion | LSASS Memory | 1 Virtualization/Sandbox Evasion | Remote Desktop Protocol | Data from Removable Media | 1 Ingress Tool Transfer | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 1 Process Injection | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | 2 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 Extra Window Memory Injection | NTDS | 1 File and Directory Discovery | Distributed Component Object Model | Input Capture | 13 Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | Software Packing | LSA Secrets | 2 System Information Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
23% | Virustotal | Browse | ||
33% | ReversingLabs | Document-Word.Trojan.Heuristic |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
smol.re | 104.21.20.196 | true | false | high | |
a726.dscd.akamai.net | 23.205.104.9 | true | false | high | |
s-0005.dual-s-msedge.net | 52.123.128.14 | true | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true |
| unknown | |
true |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
203.202.232.170 | unknown | India | 133309 | ACCESSSMART-ASAccessSmartSolutionsIndiaPvtLtdIN | true | |
104.21.20.196 | smol.re | United States | 13335 | CLOUDFLARENETUS | false |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1668132 |
Start date and time: | 2025-04-18 06:55:06 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 34s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowsofficecookbook.jbs |
Analysis system description: | Windows 11 23H2 with Office Professional Plus 2021, Chrome 131, Firefox 133, Adobe Reader DC 24, Java 8 Update 431, 7zip 24.09 |
Run name: | Potential for more IOCs and behavior |
Number of analysed new started processes analysed: | 22 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | FFL-2025-00947 PAYMENT.docx.doc |
Detection: | MAL |
Classification: | mal60.evad.winDOC@2/1@1/2 |
Cookbook Comments: |
|
- Exclude process from analysis
(whitelisted): dllhost.exe, sp psvc.exe, SystemSettingsBroker .exe, SIHClient.exe, appidcert storecheck.exe, conhost.exe, s vchost.exe - Excluded IPs from analysis (wh
itelisted): 52.109.20.38, 52.1 09.4.7, 20.189.173.16, 52.109. 16.112, 52.111.230.27, 52.111. 230.25, 52.111.230.24, 52.111. 230.26, 23.39.223.132, 23.39.2 23.146, 52.123.128.14, 20.190. 157.15, 23.205.104.9, 4.245.16 3.56 - Excluded domains from analysis
(whitelisted): us1.odcsm1.liv e.com.akadns.net, odc.officeap ps.live.com, slscr.update.micr osoft.com, scus-azsc-config.of ficeapps.live.com, templatesme tadata.office.net.edgekey.net, res-1.cdn.office.net, osiprod -ncus-buff-azsc-000.northcentr alus.cloudapp.azure.com, prod- eus-resolver.naturallanguageed itorservice.osi.office.net.aka dns.net, mobile.events.data.mi crosoft.com, ncus-azsc-000.roa ming.officeapps.live.com, roam ing.officeapps.live.com, dual- s-0005-office.config.skype.com , login.live.com, officeclient .microsoft.com, osiprod-eus2-b ronze-azsc-000.eastus2.cloudap p.azure.com, templatesmetadata .office.net, c.pki.goog, ecs.o ffice.com, prod.configsvc1.liv e.com.akadns.net, ctldl.window supdate.com, prod-na.naturalla nguageeditorservice.osi.office .net.akadns.net, prod.roaming1 .live.com.akadns.net, onedscol prdwus17.westus.cloudapp.azure .com, res-stls-prod.edgesuite. net, fe3cr.delivery.mp.microso ft.com, us1.roaming1.live.com. akadns.net, eus2-azsc-000.odc. officeapps.live.com, prod1.nat ural - Not all processes where analyz
ed, report is missing behavior information - Report size getting too big, t
oo many NtQueryAttributesFile calls found. - Report size getting too big, t
oo many NtQueryValueKey calls found. - Report size getting too big, t
oo many NtReadVirtualMemory ca lls found. - Report size getting too big, t
oo many NtSetValueKey calls fo und. - Some HTTP raw data packets hav
e been limited to 10 per sessi on. Please view the PCAPs for the complete data.
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
203.202.232.170 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
104.21.20.196 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | HTMLPhisher, Invisible JS | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
smol.re | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
a726.dscd.akamai.net | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher, Invisible JS, Tycoon2FA | Browse |
| ||
Get hash | malicious | HTMLPhisher, Invisible JS, Tycoon2FA | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
s-0005.dual-s-msedge.net | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | HTMLPhisher, Invisible JS, Tycoon2FA | Browse |
| ||
Get hash | malicious | HTMLPhisher, Invisible JS, Tycoon2FA | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher, Invisible JS, Tycoon2FA | Browse |
| ||
Get hash | malicious | HTMLPhisher, Invisible JS, Tycoon2FA | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher, Invisible JS, Tycoon2FA | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
ACCESSSMART-ASAccessSmartSolutionsIndiaPvtLtdIN | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
CLOUDFLARENETUS | Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| |
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | MSIL Logger, MassLogger RAT | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
258a5a1e95b8a911872bae9081526644 | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Process: | C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 162 |
Entropy (8bit): | 2.9248237852297185 |
Encrypted: | false |
SSDEEP: | 3:blRmMY+09cKbl6X/flY/iX0YlDQbVDxV:bzmMYfV+X9yP |
MD5: | CA01F3422AF79CF624468FD8F544B361 |
SHA1: | E2FF2FF699F8CA54E0B572A59659E9412FC07CC6 |
SHA-256: | 434628A199AA79698450CDDE5ECE14B2EB32FB7D2EE7D4DC0820199750A34C6E |
SHA-512: | 982495E3092D138AFAA5075FED0F52FE1E696D12366EB318269E703443F8E354976259ED791E8A845A7B4C353FACDE7F2A54E22597FAFE07CF6B678F705728A9 |
Malicious: | false |
Reputation: | low |
Preview: |
File type: | |
Entropy (8bit): | 7.965934074424309 |
TrID: |
|
File name: | FFL-2025-00947 PAYMENT.docx.doc |
File size: | 57'160 bytes |
MD5: | 78a0ad27916c36ecee03aa248e3f419a |
SHA1: | 742d6c84bb558d2a759a35af2588bf35d6f8bd13 |
SHA256: | 8ecb35498bed6edbe4bd53ce6d9cd46ef2bead452af5f407a6b65a5e0640591d |
SHA512: | b9f59503836cdd0bba04fc5e0e893114880abe073ee44d25ef431875b75910f44d91cea65b2099a66c142bf2a27cff580a55925ab9ac90b7c7022bbf890fcef8 |
SSDEEP: | 1536:lCwOyeJcM4ZeFbBxK7TLtMSrbz7USCwO6H+m35iweb9j:lCwOyeWMoepWd58yH+oneb9j |
TLSH: | 9F43E066751504C1C71EC67A9706A568FA8CB28EC7AFF271137877FC4EBB4ED4A02184 |
File Content Preview: | PK...........Z..K.............[Content_Types].xmlUT....2.h.2.h.2.h..]K.0.....C..h.M..u^.q......t.6.$G...'..2.:...BI..y.9i..Uc...B...lT.Y.V:...d.....e..U.v.J......'...C.Hmc......(.`D,..K+..F ..9.B..9..px.....sL.l:y..A+..E.{a..?\P.r..C.......%t......)8..j.. |
Icon Hash: | 35e1cc889a8a8599 |
Document Type: | OpenXML |
Number of OLE Files: | 1 |
Has Summary Info: | |
Application Name: | |
Encrypted Document: | False |
Contains Word Document Stream: | True |
Contains Workbook/Book Stream: | False |
Contains PowerPoint Document Stream: | False |
Contains Visio Document Stream: | False |
Contains ObjectPool Stream: | False |
Flash Objects Count: | 0 |
Contains VBA Macros: | False |
Code Page: | 1252 |
Title: | |
Subject: | |
Author: | 91974 |
Keywords: | |
Template: | |
Last Saved By: | 91974 |
Revion Number: | 2 |
Total Edit Time: | 0 |
Last Printed: | 2024-11-08 04:15:17 |
Create Time: | 2025-04-16T00:41:00Z |
Last Saved Time: | 2025-04-16T00:41:00Z |
Number of Pages: | 1 |
Number of Words: | 0 |
Number of Characters: | 0 |
Thumbnail: | 0&" WMFC #ClOb EMFC)8X?F, EMF+@xxF\PEMF+"@@$@0@?!@@!"!"!"!P"!P"!P'%&%"6"%Ld"""!??%6#%Ld""!??%,6#,%Ld,",,"!??%I6#I%LdI"II"!??%_6#_%Ld_"__"!??%u6#u%Ldu"uu"!??%6#%Ld""!??%6#%Ld""!??%6#%Ld""!??%6#%Ld""!??%"6P%Ld"O".!??%"6"%Ld"""!??%C6C%LdCCC!??%6%Ld!??%O6O%LdOOO!??'%Ld!!!??%%6"%Ld!!!??%6%Ld!??'%(&%6"%Ld! !??%6%Ld!??'%(&%6"%Ld! !??%!6!%Ld!!!!??!bK!;$$==V(X(($$AA<C%'%%V0%%('%%V0%%('%%V0%%('%%V0%%('%%V0%%('%%V0%%('%%V0%%('%%V0%%('%%V0%%('%%V0%%('%%V0%%('%%V0%%('%%V0%%('%%V0%%(%""RpArialv;xW%lu-aRlu`W`RxW/YW/YPZW{/YluO/YYI/ Y)I/%j";j"/k3Xv9YuXudv%'A>TT+UUA&ALP1TT6HUUA&A6LP2TTL^UUA&ALLP3TTbtUUA&AbLP4TTwUUA&AwLP5TTUUA&ALP6TTUUA&ALP7TTUUA&ALP8TT.8UUA&A.LPATTUUA&ALPBTTUUA&ALPC%%"!%'A>#PRp Arialv;%lu<aRlu`R/!/!!{/!uO/! I/ !L>I/%N;Na#/Mzdv9t &" WMFC Cudv%Rp Arialv;!luftaRlu`R/!/!!{/!uO/! I/ !\dI/%J;Ja#/Izdv9t udv%T|GL^UUA&AGLL\Exporter'%LdG]^G]E!??%Rp Arialv;%lu-aRlu`R/!/!!{/!uO/! I/ !dI/%K;Ka#/Jzdv9t udv%TGbOtUUA&AGbLJAI LARA DRUGS PRIVATE LIMITEDRp Arialv;%lu-aRlu\C`R/\C!\C/!\C!{/!uO/! I/ !bI/%H;Ha#/Gzdv9t \Cu\Cdv%THGwOUUA&AGw*LCor.Off: "LARA HOUSE " D.NO.:5-5-35/259/2,TtGOUUA&AG1LOPP.KIDZEE SCHOOL,PLOT No.:55, MAITRINAGAR COLONYTGUUA&AGLx(BACKSIDE METRO MALL)T\GOUUA&AG-LKUKATPALLY,HYDERABAD-500072, TELANGANA, INDIA%(%%%"!%D-PITxUUA&AQ.L\INVOICE%%%"!%#P%"!%P'%(&%",6C,%Ld",B,",!!??%C6C,%LdCC+C!??%"I6CI%Ld"IBI"I!!??%6,%Ld+!??%O6O,%LdOO+O!??%"_6C_%Ld"_B_"_!!??%"u6Cu%Ld"uBu"u!!??%"6C%Ld"B"!!??%"6C%Ld"B"!!??%OJ6O`%LdOJO_OJ!??%"6C%Ld"B"!!??%"6C%Ld"B"!!??%J6`%LdJ_J!??%O6O%LdOOO!??%"6"%Ld"""!??'%(&%C,6C%LdC,CC,!??%((&%6%Ld!??%O6O%LdO!??%"6Q%Ld"O"/!??'%(&%D,6Q,%LdD,O,D,!??%DI6QI%LdDIOIDI!??%((&%D_6Q_%LdD_O_D_!??%Du6Qu%LdDuOuDu!??%D6Q%LdDOD!??%D6Q%LdDOD!??%D6Q%LdDOD!??%D6Q%LdDOD!??&WMFCC%%"!%#P%"!%P'%(&%6P%LdOP!??%6%Ld!??%"Q|OP(xP( F4(EMF+*@$??FEMF+@P''',P',P',P--""-@!"-#-@!"-,,#-@!",-II#-@!"I-__#-@!"_-uu#-@!"u-#-@!"-#-@!"-#-@!"-#-@!"-"P-@!."-""-@!"-CC-@!C--@!-OO-@!O-@!!--"-@!!--@!--"-@! --@!--"-@! -!!-@!!,---$----$----$----$----$----$----$----$----$----$----$----$----$----$---''Arial-'A>212622L32b42w52627282.A2B2C-"System-'-'A>,P# Arial- Arial-2LGExporter-@!E]G- Arial-42bGJAI LARA DRUGS PRIVATE LIMITED Arial-F2wG*Cor.Off: "LARA HOUSE " D.NO.:5-5-35/259/2,Q2G1OPP.KIDZEE SCHOOL,PLOT No.:55, MAITRINAGAR COLONY'2G(BACKSIDE METRO MALL)K2G-KUKATPALLY,HYDERABAD-500072, TELANGANA, INDIA----'-,IP-D2.QINVOICE---'-,P#-'-,P--,",C-@!!,"-C,C-@!C-I"IC-@!!I"-,-@!-O,O-@!O-_"_C-@!!_"-u"uC-@!!u"-"C-@!!"-"C-@!!"-JO`O-@!JO-"C-@!!"-"C-@!!"-J`-@!J-OO-@!O-""-@!"--,CC-@!,C---@!-OO-@!O-"Q-@!/"--,D,Q-@!,D-IDIQ-@!ID--_D_Q-@!_D-uDuQ-@!uD-DQ-@!D-DQ-@!D-DQ-@!D-DQ-@!D--'-,P#-'-,P--P-@!P--@!-'#AP( |
Creating Application: | |
Security: | 0 |
Document Code Page: | 1252 |
Number of Lines: | 1 |
Number of Paragraphs: | 1 |
Thumbnail Scaling Desired: | false |
Company: | |
Contains Dirty Links: | false |
Shared Document: | false |
Changed Hyperlinks: | false |
Application Version: | 12.0000 |
General | |
Stream Path: | \x1CompObj |
CLSID: | |
File Type: | data |
Stream Size: | 114 |
Entropy: | 4.25248375192737 |
Base64 Encoded: | True |
Data ASCII: | . . . . . . . . . . . . . . . . . . . F & . . . M i c r o s o f t O f f i c e E x c e l 2 0 0 3 W o r k s h e e t . . . . . B i f f 8 . . . . . E x c e l . S h e e t . 8 . 9 q . . . . . . . . . . . . |
Data Raw: | 01 00 fe ff 03 0a 00 00 ff ff ff ff 20 08 02 00 00 00 00 00 c0 00 00 00 00 00 00 46 26 00 00 00 4d 69 63 72 6f 73 6f 66 74 20 4f 66 66 69 63 65 20 45 78 63 65 6c 20 32 30 30 33 20 57 6f 72 6b 73 68 65 65 74 00 06 00 00 00 42 69 66 66 38 00 0e 00 00 00 45 78 63 65 6c 2e 53 68 65 65 74 2e 38 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00 |
General | |
Stream Path: | \x1Ole |
CLSID: | |
File Type: | data |
Stream Size: | 20 |
Entropy: | 0.5689955935892812 |
Base64 Encoded: | False |
Data ASCII: | . . . . . . . . . . . . . . . . . . . . |
Data Raw: | 01 00 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |
General | |
Stream Path: | \x3EPRINT |
CLSID: | |
File Type: | Windows Enhanced Metafile (EMF) image data version 0x10000 |
Stream Size: | 56832 |
Entropy: | 3.196382270410016 |
Base64 Encoded: | False |
Data ASCII: | . . . . l . . . . . . . . . . . ! . . . . . . . . . . . . . T . . ! q . . E M F . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . \\ K . . h C . . F . . . , . . . . . . E M F + . @ . . . . . . . . . . . . . . . . X . . . X . . . F . . . \\ . . . P . . . E M F + " @ . . . . . . . . . . . @ . . . . . . . . . . $ @ . . . . . . . . . . 0 @ . . . . . . . . . . . . ? ! @ . . . . . . . . . . . @ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . |
Data Raw: | 01 00 00 00 6c 00 00 00 a9 00 00 00 00 00 00 00 00 21 00 00 c2 1a 00 00 00 00 00 00 00 00 00 00 54 8c 00 00 21 71 00 00 20 45 4d 46 00 00 01 00 00 de 00 00 fc 05 00 00 0d 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ec 13 00 00 c8 19 00 00 d8 00 00 00 17 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 5c 4b 03 00 68 43 04 00 46 00 00 00 2c 00 00 00 20 00 00 00 45 4d 46 2b 01 40 01 00 |
General | |
Stream Path: | \x3ObjInfo |
CLSID: | |
File Type: | data |
Stream Size: | 6 |
Entropy: | 1.2516291673878228 |
Base64 Encoded: | False |
Data ASCII: | . . . . . . |
Data Raw: | 00 00 03 00 0d 00 |
General | |
Stream Path: | \x5DocumentSummaryInformation |
CLSID: | |
File Type: | data |
Stream Size: | 356 |
Entropy: | 3.7776304393687803 |
Base64 Encoded: | False |
Data ASCII: | . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . + , 0 . . . 4 . . . . . . . . . . . P . . . . . . . X . . . . . . . l . . . . . . . t . . . . . . . | . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . H E T R O D R U G S . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . I N V O I C E . . . . . P K G L I S T . . . . . S h e e t 1 . . . . . I N V O I C E ! P r i n t _ A r e a . . . . . ' P K |
Data Raw: | fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 02 d5 cd d5 9c 2e 1b 10 93 97 08 00 2b 2c f9 ae 30 00 00 00 34 01 00 00 09 00 00 00 01 00 00 00 50 00 00 00 0f 00 00 00 58 00 00 00 17 00 00 00 6c 00 00 00 0b 00 00 00 74 00 00 00 10 00 00 00 7c 00 00 00 13 00 00 00 84 00 00 00 16 00 00 00 8c 00 00 00 0d 00 00 00 94 00 00 00 0c 00 00 00 f1 00 00 00 |
General | |
Stream Path: | \x5SummaryInformation |
CLSID: | |
File Type: | data |
Stream Size: | 25116 |
Entropy: | 3.0683208466933096 |
Base64 Encoded: | True |
Data ASCII: | . . . . . . . . . . . . . . . . . . . . . . . . . . O h . . . + ' 0 . . . a . . . . . . . . . . P . . . . . . . X . . . . . . . l . . . . . . . | . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . B . S . R E D D Y . . . . . . . . . . . 9 1 9 7 4 . . . . . . . . . . . M i c r o s o f t E x c e l . @ . . . x . . 1 . @ . . . . . . . @ . . . < N h . . . . . . . . . G . . . $ a . . . . . . . . . . . . . . . . . . 0 . . . . . . . . . . . . . . & . . . " |
Data Raw: | fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 e0 85 9f f2 f9 4f 68 10 ab 91 08 00 2b 27 b3 d9 30 00 00 00 ec 61 00 00 09 00 00 00 01 00 00 00 50 00 00 00 04 00 00 00 58 00 00 00 08 00 00 00 6c 00 00 00 12 00 00 00 7c 00 00 00 0b 00 00 00 94 00 00 00 0c 00 00 00 a0 00 00 00 0d 00 00 00 ac 00 00 00 13 00 00 00 b8 00 00 00 11 00 00 00 c0 00 00 00 |
General | |
Stream Path: | Workbook |
CLSID: | |
File Type: | Applesoft BASIC program data, first line number 16 |
Stream Size: | 49884 |
Entropy: | 3.9936426036867276 |
Base64 Encoded: | True |
Data ASCII: | . . . . . . . . . . . . . . . . . . . . . . . . . . . . . \\ . p . . . . 9 1 9 7 4 B . . . . a . . . . . . . . = . . . . . . . . . . . . . . . . . . . . = . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . = . . . x . . $ ` . 9 . . . . . . . Y . @ . . . . . . . . . . " . . . . . . . . . . . . |
Data Raw: | 09 08 10 00 00 06 05 00 ab 1f cd 07 c9 00 02 00 06 04 00 00 e1 00 02 00 b0 04 c1 00 02 00 00 00 e2 00 00 00 5c 00 70 00 05 00 00 39 31 39 37 34 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 |
Download Network PCAP: filtered – full
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-04-18T06:56:09.820739+0200 | 1810005 | Joe Security ANOMALY Microsoft Office WebDAV Discovery | 1 | 192.168.2.24 | 60828 | 104.21.20.196 | 443 | TCP |
2025-04-18T06:56:12.160852+0200 | 1810004 | Joe Security ANOMALY Microsoft Office HTTP activity | 1 | 192.168.2.24 | 60832 | 104.21.20.196 | 443 | TCP |
2025-04-18T06:56:12.681332+0200 | 1810004 | Joe Security ANOMALY Microsoft Office HTTP activity | 1 | 192.168.2.24 | 60834 | 203.202.232.170 | 80 | TCP |
- Total Packets: 105
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Apr 18, 2025 06:56:08.153825998 CEST | 60827 | 443 | 192.168.2.24 | 104.21.20.196 |
Apr 18, 2025 06:56:08.153873920 CEST | 443 | 60827 | 104.21.20.196 | 192.168.2.24 |
Apr 18, 2025 06:56:08.153928041 CEST | 60827 | 443 | 192.168.2.24 | 104.21.20.196 |
Apr 18, 2025 06:56:08.154412031 CEST | 60827 | 443 | 192.168.2.24 | 104.21.20.196 |
Apr 18, 2025 06:56:08.154433012 CEST | 443 | 60827 | 104.21.20.196 | 192.168.2.24 |
Apr 18, 2025 06:56:08.371977091 CEST | 443 | 60827 | 104.21.20.196 | 192.168.2.24 |
Apr 18, 2025 06:56:08.372261047 CEST | 60827 | 443 | 192.168.2.24 | 104.21.20.196 |
Apr 18, 2025 06:56:08.467639923 CEST | 60827 | 443 | 192.168.2.24 | 104.21.20.196 |
Apr 18, 2025 06:56:08.467668056 CEST | 443 | 60827 | 104.21.20.196 | 192.168.2.24 |
Apr 18, 2025 06:56:08.468061924 CEST | 443 | 60827 | 104.21.20.196 | 192.168.2.24 |
Apr 18, 2025 06:56:08.470716000 CEST | 60827 | 443 | 192.168.2.24 | 104.21.20.196 |
Apr 18, 2025 06:56:08.512279987 CEST | 443 | 60827 | 104.21.20.196 | 192.168.2.24 |
Apr 18, 2025 06:56:08.957946062 CEST | 443 | 60827 | 104.21.20.196 | 192.168.2.24 |
Apr 18, 2025 06:56:08.958084106 CEST | 443 | 60827 | 104.21.20.196 | 192.168.2.24 |
Apr 18, 2025 06:56:08.958147049 CEST | 60827 | 443 | 192.168.2.24 | 104.21.20.196 |
Apr 18, 2025 06:56:08.959454060 CEST | 60827 | 443 | 192.168.2.24 | 104.21.20.196 |
Apr 18, 2025 06:56:08.959475040 CEST | 443 | 60827 | 104.21.20.196 | 192.168.2.24 |
Apr 18, 2025 06:56:09.004196882 CEST | 60828 | 443 | 192.168.2.24 | 104.21.20.196 |
Apr 18, 2025 06:56:09.004260063 CEST | 443 | 60828 | 104.21.20.196 | 192.168.2.24 |
Apr 18, 2025 06:56:09.004326105 CEST | 60828 | 443 | 192.168.2.24 | 104.21.20.196 |
Apr 18, 2025 06:56:09.005765915 CEST | 60828 | 443 | 192.168.2.24 | 104.21.20.196 |
Apr 18, 2025 06:56:09.005785942 CEST | 443 | 60828 | 104.21.20.196 | 192.168.2.24 |
Apr 18, 2025 06:56:09.217961073 CEST | 443 | 60828 | 104.21.20.196 | 192.168.2.24 |
Apr 18, 2025 06:56:09.218029976 CEST | 60828 | 443 | 192.168.2.24 | 104.21.20.196 |
Apr 18, 2025 06:56:09.219425917 CEST | 60828 | 443 | 192.168.2.24 | 104.21.20.196 |
Apr 18, 2025 06:56:09.219440937 CEST | 443 | 60828 | 104.21.20.196 | 192.168.2.24 |
Apr 18, 2025 06:56:09.220341921 CEST | 443 | 60828 | 104.21.20.196 | 192.168.2.24 |
Apr 18, 2025 06:56:09.220402002 CEST | 60828 | 443 | 192.168.2.24 | 104.21.20.196 |
Apr 18, 2025 06:56:09.221816063 CEST | 60828 | 443 | 192.168.2.24 | 104.21.20.196 |
Apr 18, 2025 06:56:09.221879959 CEST | 443 | 60828 | 104.21.20.196 | 192.168.2.24 |
Apr 18, 2025 06:56:09.221920013 CEST | 60828 | 443 | 192.168.2.24 | 104.21.20.196 |
Apr 18, 2025 06:56:09.221927881 CEST | 443 | 60828 | 104.21.20.196 | 192.168.2.24 |
Apr 18, 2025 06:56:09.221962929 CEST | 60828 | 443 | 192.168.2.24 | 104.21.20.196 |
Apr 18, 2025 06:56:09.225073099 CEST | 60828 | 443 | 192.168.2.24 | 104.21.20.196 |
Apr 18, 2025 06:56:09.272269964 CEST | 443 | 60828 | 104.21.20.196 | 192.168.2.24 |
Apr 18, 2025 06:56:09.820750952 CEST | 443 | 60828 | 104.21.20.196 | 192.168.2.24 |
Apr 18, 2025 06:56:09.820820093 CEST | 60828 | 443 | 192.168.2.24 | 104.21.20.196 |
Apr 18, 2025 06:56:09.820833921 CEST | 443 | 60828 | 104.21.20.196 | 192.168.2.24 |
Apr 18, 2025 06:56:09.820910931 CEST | 443 | 60828 | 104.21.20.196 | 192.168.2.24 |
Apr 18, 2025 06:56:09.820935965 CEST | 60828 | 443 | 192.168.2.24 | 104.21.20.196 |
Apr 18, 2025 06:56:09.821002960 CEST | 60828 | 443 | 192.168.2.24 | 104.21.20.196 |
Apr 18, 2025 06:56:09.824924946 CEST | 60828 | 443 | 192.168.2.24 | 104.21.20.196 |
Apr 18, 2025 06:56:09.824938059 CEST | 443 | 60828 | 104.21.20.196 | 192.168.2.24 |
Apr 18, 2025 06:56:09.824951887 CEST | 60828 | 443 | 192.168.2.24 | 104.21.20.196 |
Apr 18, 2025 06:56:09.824991941 CEST | 60828 | 443 | 192.168.2.24 | 104.21.20.196 |
Apr 18, 2025 06:56:09.869139910 CEST | 60829 | 443 | 192.168.2.24 | 104.21.20.196 |
Apr 18, 2025 06:56:09.869194031 CEST | 443 | 60829 | 104.21.20.196 | 192.168.2.24 |
Apr 18, 2025 06:56:09.869272947 CEST | 60829 | 443 | 192.168.2.24 | 104.21.20.196 |
Apr 18, 2025 06:56:09.869523048 CEST | 60829 | 443 | 192.168.2.24 | 104.21.20.196 |
Apr 18, 2025 06:56:09.869539022 CEST | 443 | 60829 | 104.21.20.196 | 192.168.2.24 |
Apr 18, 2025 06:56:10.083878040 CEST | 443 | 60829 | 104.21.20.196 | 192.168.2.24 |
Apr 18, 2025 06:56:10.084559917 CEST | 60829 | 443 | 192.168.2.24 | 104.21.20.196 |
Apr 18, 2025 06:56:10.084584951 CEST | 443 | 60829 | 104.21.20.196 | 192.168.2.24 |
Apr 18, 2025 06:56:10.085078955 CEST | 60829 | 443 | 192.168.2.24 | 104.21.20.196 |
Apr 18, 2025 06:56:10.085083008 CEST | 443 | 60829 | 104.21.20.196 | 192.168.2.24 |
Apr 18, 2025 06:56:10.690697908 CEST | 443 | 60829 | 104.21.20.196 | 192.168.2.24 |
Apr 18, 2025 06:56:10.690766096 CEST | 443 | 60829 | 104.21.20.196 | 192.168.2.24 |
Apr 18, 2025 06:56:10.690839052 CEST | 60829 | 443 | 192.168.2.24 | 104.21.20.196 |
Apr 18, 2025 06:56:10.693094969 CEST | 60829 | 443 | 192.168.2.24 | 104.21.20.196 |
Apr 18, 2025 06:56:10.693119049 CEST | 443 | 60829 | 104.21.20.196 | 192.168.2.24 |
Apr 18, 2025 06:56:10.693134069 CEST | 60829 | 443 | 192.168.2.24 | 104.21.20.196 |
Apr 18, 2025 06:56:10.693140984 CEST | 443 | 60829 | 104.21.20.196 | 192.168.2.24 |
Apr 18, 2025 06:56:10.701306105 CEST | 60830 | 80 | 192.168.2.24 | 203.202.232.170 |
Apr 18, 2025 06:56:10.954657078 CEST | 80 | 60830 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:10.954790115 CEST | 60830 | 80 | 192.168.2.24 | 203.202.232.170 |
Apr 18, 2025 06:56:10.956494093 CEST | 60830 | 80 | 192.168.2.24 | 203.202.232.170 |
Apr 18, 2025 06:56:11.214211941 CEST | 80 | 60830 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:11.265283108 CEST | 60830 | 80 | 192.168.2.24 | 203.202.232.170 |
Apr 18, 2025 06:56:11.336605072 CEST | 60832 | 443 | 192.168.2.24 | 104.21.20.196 |
Apr 18, 2025 06:56:11.336667061 CEST | 443 | 60832 | 104.21.20.196 | 192.168.2.24 |
Apr 18, 2025 06:56:11.336754084 CEST | 60832 | 443 | 192.168.2.24 | 104.21.20.196 |
Apr 18, 2025 06:56:11.337763071 CEST | 60832 | 443 | 192.168.2.24 | 104.21.20.196 |
Apr 18, 2025 06:56:11.337781906 CEST | 443 | 60832 | 104.21.20.196 | 192.168.2.24 |
Apr 18, 2025 06:56:11.555372953 CEST | 443 | 60832 | 104.21.20.196 | 192.168.2.24 |
Apr 18, 2025 06:56:11.555449009 CEST | 60832 | 443 | 192.168.2.24 | 104.21.20.196 |
Apr 18, 2025 06:56:11.557248116 CEST | 60832 | 443 | 192.168.2.24 | 104.21.20.196 |
Apr 18, 2025 06:56:11.557260036 CEST | 443 | 60832 | 104.21.20.196 | 192.168.2.24 |
Apr 18, 2025 06:56:11.557667971 CEST | 443 | 60832 | 104.21.20.196 | 192.168.2.24 |
Apr 18, 2025 06:56:11.557725906 CEST | 60832 | 443 | 192.168.2.24 | 104.21.20.196 |
Apr 18, 2025 06:56:11.558506012 CEST | 60832 | 443 | 192.168.2.24 | 104.21.20.196 |
Apr 18, 2025 06:56:11.558583021 CEST | 443 | 60832 | 104.21.20.196 | 192.168.2.24 |
Apr 18, 2025 06:56:11.558636904 CEST | 60832 | 443 | 192.168.2.24 | 104.21.20.196 |
Apr 18, 2025 06:56:11.558698893 CEST | 60832 | 443 | 192.168.2.24 | 104.21.20.196 |
Apr 18, 2025 06:56:11.600274086 CEST | 443 | 60832 | 104.21.20.196 | 192.168.2.24 |
Apr 18, 2025 06:56:12.160933018 CEST | 443 | 60832 | 104.21.20.196 | 192.168.2.24 |
Apr 18, 2025 06:56:12.161011934 CEST | 60832 | 443 | 192.168.2.24 | 104.21.20.196 |
Apr 18, 2025 06:56:12.161041021 CEST | 443 | 60832 | 104.21.20.196 | 192.168.2.24 |
Apr 18, 2025 06:56:12.161111116 CEST | 60832 | 443 | 192.168.2.24 | 104.21.20.196 |
Apr 18, 2025 06:56:12.161151886 CEST | 443 | 60832 | 104.21.20.196 | 192.168.2.24 |
Apr 18, 2025 06:56:12.161202908 CEST | 60832 | 443 | 192.168.2.24 | 104.21.20.196 |
Apr 18, 2025 06:56:12.162719011 CEST | 60832 | 443 | 192.168.2.24 | 104.21.20.196 |
Apr 18, 2025 06:56:12.162734032 CEST | 443 | 60832 | 104.21.20.196 | 192.168.2.24 |
Apr 18, 2025 06:56:12.164305925 CEST | 60834 | 80 | 192.168.2.24 | 203.202.232.170 |
Apr 18, 2025 06:56:12.421092987 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:12.422878981 CEST | 60834 | 80 | 192.168.2.24 | 203.202.232.170 |
Apr 18, 2025 06:56:12.423110962 CEST | 60834 | 80 | 192.168.2.24 | 203.202.232.170 |
Apr 18, 2025 06:56:12.681274891 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:12.681298971 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:12.681317091 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:12.681332111 CEST | 60834 | 80 | 192.168.2.24 | 203.202.232.170 |
Apr 18, 2025 06:56:12.681335926 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:12.681354046 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:12.681365967 CEST | 60834 | 80 | 192.168.2.24 | 203.202.232.170 |
Apr 18, 2025 06:56:12.681371927 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:12.681391001 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:12.681392908 CEST | 60834 | 80 | 192.168.2.24 | 203.202.232.170 |
Apr 18, 2025 06:56:12.681407928 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:12.681408882 CEST | 60834 | 80 | 192.168.2.24 | 203.202.232.170 |
Apr 18, 2025 06:56:12.681427002 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:12.681441069 CEST | 60834 | 80 | 192.168.2.24 | 203.202.232.170 |
Apr 18, 2025 06:56:12.681446075 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:12.681468010 CEST | 60834 | 80 | 192.168.2.24 | 203.202.232.170 |
Apr 18, 2025 06:56:12.681493044 CEST | 60834 | 80 | 192.168.2.24 | 203.202.232.170 |
Apr 18, 2025 06:56:12.938322067 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:12.938380957 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:12.938404083 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:12.938411951 CEST | 60834 | 80 | 192.168.2.24 | 203.202.232.170 |
Apr 18, 2025 06:56:12.938421965 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:12.938441992 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:12.938460112 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:12.938476086 CEST | 60834 | 80 | 192.168.2.24 | 203.202.232.170 |
Apr 18, 2025 06:56:12.938477039 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:12.938496113 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:12.938515902 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:12.938522100 CEST | 60834 | 80 | 192.168.2.24 | 203.202.232.170 |
Apr 18, 2025 06:56:12.938533068 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:12.938549995 CEST | 60834 | 80 | 192.168.2.24 | 203.202.232.170 |
Apr 18, 2025 06:56:12.938549995 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:12.938568115 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:12.938569069 CEST | 60834 | 80 | 192.168.2.24 | 203.202.232.170 |
Apr 18, 2025 06:56:12.938586950 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:12.938586950 CEST | 60834 | 80 | 192.168.2.24 | 203.202.232.170 |
Apr 18, 2025 06:56:12.938605070 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:12.938615084 CEST | 60834 | 80 | 192.168.2.24 | 203.202.232.170 |
Apr 18, 2025 06:56:12.938621998 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:12.938637018 CEST | 60834 | 80 | 192.168.2.24 | 203.202.232.170 |
Apr 18, 2025 06:56:12.938683987 CEST | 60834 | 80 | 192.168.2.24 | 203.202.232.170 |
Apr 18, 2025 06:56:12.938685894 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:12.938709021 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:12.938728094 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:12.938749075 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:12.938750029 CEST | 60834 | 80 | 192.168.2.24 | 203.202.232.170 |
Apr 18, 2025 06:56:12.938771009 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:12.938777924 CEST | 60834 | 80 | 192.168.2.24 | 203.202.232.170 |
Apr 18, 2025 06:56:12.938802004 CEST | 60834 | 80 | 192.168.2.24 | 203.202.232.170 |
Apr 18, 2025 06:56:12.938952923 CEST | 60834 | 80 | 192.168.2.24 | 203.202.232.170 |
Apr 18, 2025 06:56:13.207041979 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:13.207051992 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:13.207057953 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:13.207063913 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:13.207070112 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:13.207076073 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:13.207088947 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:13.207096100 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:13.207102060 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:13.207108021 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:13.207122087 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:13.207129955 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:13.207135916 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:13.207138062 CEST | 60834 | 80 | 192.168.2.24 | 203.202.232.170 |
Apr 18, 2025 06:56:13.207148075 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:13.207154036 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:13.207165956 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:13.207171917 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:13.207184076 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:13.207189083 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:13.207195044 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:13.207201958 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:13.207206964 CEST | 60834 | 80 | 192.168.2.24 | 203.202.232.170 |
Apr 18, 2025 06:56:13.207207918 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:13.207221031 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:13.207226992 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:13.207232952 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:13.207238913 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:13.207242012 CEST | 60834 | 80 | 192.168.2.24 | 203.202.232.170 |
Apr 18, 2025 06:56:13.207247019 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:13.207259893 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:13.207266092 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:13.207272053 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:13.207272053 CEST | 60834 | 80 | 192.168.2.24 | 203.202.232.170 |
Apr 18, 2025 06:56:13.207297087 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:13.207298994 CEST | 60834 | 80 | 192.168.2.24 | 203.202.232.170 |
Apr 18, 2025 06:56:13.207304001 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:13.207309961 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:13.207321882 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:13.207329988 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:13.207335949 CEST | 60834 | 80 | 192.168.2.24 | 203.202.232.170 |
Apr 18, 2025 06:56:13.207336903 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:13.207349062 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:13.207360029 CEST | 60834 | 80 | 192.168.2.24 | 203.202.232.170 |
Apr 18, 2025 06:56:13.207386971 CEST | 60834 | 80 | 192.168.2.24 | 203.202.232.170 |
Apr 18, 2025 06:56:13.275294065 CEST | 60838 | 443 | 192.168.2.24 | 104.21.20.196 |
Apr 18, 2025 06:56:13.275346994 CEST | 443 | 60838 | 104.21.20.196 | 192.168.2.24 |
Apr 18, 2025 06:56:13.275494099 CEST | 60838 | 443 | 192.168.2.24 | 104.21.20.196 |
Apr 18, 2025 06:56:13.276309013 CEST | 60838 | 443 | 192.168.2.24 | 104.21.20.196 |
Apr 18, 2025 06:56:13.276335001 CEST | 443 | 60838 | 104.21.20.196 | 192.168.2.24 |
Apr 18, 2025 06:56:13.493900061 CEST | 443 | 60838 | 104.21.20.196 | 192.168.2.24 |
Apr 18, 2025 06:56:13.494955063 CEST | 60838 | 443 | 192.168.2.24 | 104.21.20.196 |
Apr 18, 2025 06:56:13.504594088 CEST | 60838 | 443 | 192.168.2.24 | 104.21.20.196 |
Apr 18, 2025 06:56:13.504612923 CEST | 443 | 60838 | 104.21.20.196 | 192.168.2.24 |
Apr 18, 2025 06:56:13.505064964 CEST | 443 | 60838 | 104.21.20.196 | 192.168.2.24 |
Apr 18, 2025 06:56:13.506225109 CEST | 60838 | 443 | 192.168.2.24 | 104.21.20.196 |
Apr 18, 2025 06:56:13.506954908 CEST | 60838 | 443 | 192.168.2.24 | 104.21.20.196 |
Apr 18, 2025 06:56:13.507164001 CEST | 443 | 60838 | 104.21.20.196 | 192.168.2.24 |
Apr 18, 2025 06:56:13.507208109 CEST | 60838 | 443 | 192.168.2.24 | 104.21.20.196 |
Apr 18, 2025 06:56:13.507266998 CEST | 60838 | 443 | 192.168.2.24 | 104.21.20.196 |
Apr 18, 2025 06:56:13.552274942 CEST | 443 | 60838 | 104.21.20.196 | 192.168.2.24 |
Apr 18, 2025 06:56:14.088000059 CEST | 443 | 60838 | 104.21.20.196 | 192.168.2.24 |
Apr 18, 2025 06:56:14.088165998 CEST | 443 | 60838 | 104.21.20.196 | 192.168.2.24 |
Apr 18, 2025 06:56:14.088294983 CEST | 60838 | 443 | 192.168.2.24 | 104.21.20.196 |
Apr 18, 2025 06:56:14.118626118 CEST | 60838 | 443 | 192.168.2.24 | 104.21.20.196 |
Apr 18, 2025 06:56:14.118626118 CEST | 60838 | 443 | 192.168.2.24 | 104.21.20.196 |
Apr 18, 2025 06:56:14.118644953 CEST | 443 | 60838 | 104.21.20.196 | 192.168.2.24 |
Apr 18, 2025 06:56:14.118833065 CEST | 60838 | 443 | 192.168.2.24 | 104.21.20.196 |
Apr 18, 2025 06:56:14.155771017 CEST | 60834 | 80 | 192.168.2.24 | 203.202.232.170 |
Apr 18, 2025 06:56:14.413861990 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:14.413940907 CEST | 60834 | 80 | 192.168.2.24 | 203.202.232.170 |
Apr 18, 2025 06:56:16.243210077 CEST | 80 | 60830 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:16.243566036 CEST | 60830 | 80 | 192.168.2.24 | 203.202.232.170 |
Apr 18, 2025 06:56:16.243685007 CEST | 60830 | 80 | 192.168.2.24 | 203.202.232.170 |
Apr 18, 2025 06:56:16.497319937 CEST | 80 | 60830 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:19.418741941 CEST | 80 | 60834 | 203.202.232.170 | 192.168.2.24 |
Apr 18, 2025 06:56:19.418821096 CEST | 60834 | 80 | 192.168.2.24 | 203.202.232.170 |
Apr 18, 2025 06:57:56.546847105 CEST | 60834 | 80 | 192.168.2.24 | 203.202.232.170 |
Apr 18, 2025 06:57:57.155855894 CEST | 60834 | 80 | 192.168.2.24 | 203.202.232.170 |
Apr 18, 2025 06:57:58.265171051 CEST | 60834 | 80 | 192.168.2.24 | 203.202.232.170 |
Apr 18, 2025 06:58:00.468296051 CEST | 60834 | 80 | 192.168.2.24 | 203.202.232.170 |
Apr 18, 2025 06:58:04.874600887 CEST | 60834 | 80 | 192.168.2.24 | 203.202.232.170 |
Apr 18, 2025 06:58:13.671472073 CEST | 60834 | 80 | 192.168.2.24 | 203.202.232.170 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Apr 18, 2025 06:56:08.041363955 CEST | 51239 | 53 | 192.168.2.24 | 1.1.1.1 |
Apr 18, 2025 06:56:08.152944088 CEST | 53 | 51239 | 1.1.1.1 | 192.168.2.24 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Apr 18, 2025 06:56:08.041363955 CEST | 192.168.2.24 | 1.1.1.1 | 0xa094 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Apr 18, 2025 06:56:07.948199034 CEST | 1.1.1.1 | 192.168.2.24 | 0x92e7 | No error (0) | s-0005.dual-s-msedge.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 18, 2025 06:56:07.948199034 CEST | 1.1.1.1 | 192.168.2.24 | 0x92e7 | No error (0) | 52.123.128.14 | A (IP address) | IN (0x0001) | false | ||
Apr 18, 2025 06:56:07.948199034 CEST | 1.1.1.1 | 192.168.2.24 | 0x92e7 | No error (0) | 52.123.129.14 | A (IP address) | IN (0x0001) | false | ||
Apr 18, 2025 06:56:08.152944088 CEST | 1.1.1.1 | 192.168.2.24 | 0xa094 | No error (0) | 104.21.20.196 | A (IP address) | IN (0x0001) | false | ||
Apr 18, 2025 06:56:08.152944088 CEST | 1.1.1.1 | 192.168.2.24 | 0xa094 | No error (0) | 172.67.194.27 | A (IP address) | IN (0x0001) | false | ||
Apr 18, 2025 06:56:15.127186060 CEST | 1.1.1.1 | 192.168.2.24 | 0xa343 | No error (0) | a726.dscd.akamai.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 18, 2025 06:56:15.127186060 CEST | 1.1.1.1 | 192.168.2.24 | 0xa343 | No error (0) | 23.205.104.9 | A (IP address) | IN (0x0001) | false | ||
Apr 18, 2025 06:56:15.127186060 CEST | 1.1.1.1 | 192.168.2.24 | 0xa343 | No error (0) | 23.205.104.45 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.24 | 60830 | 203.202.232.170 | 80 | 7056 | C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Apr 18, 2025 06:56:10.956494093 CEST | 460 | OUT | |
Apr 18, 2025 06:56:11.214211941 CEST | 322 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.24 | 60834 | 203.202.232.170 | 80 | 7056 | C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Apr 18, 2025 06:56:12.423110962 CEST | 340 | OUT | |
Apr 18, 2025 06:56:12.681274891 CEST | 1358 | IN | |
Apr 18, 2025 06:56:12.681298971 CEST | 1358 | IN | |
Apr 18, 2025 06:56:12.681317091 CEST | 1358 | IN | |
Apr 18, 2025 06:56:12.681335926 CEST | 1358 | IN | |
Apr 18, 2025 06:56:12.681354046 CEST | 1358 | IN | |
Apr 18, 2025 06:56:12.681371927 CEST | 1358 | IN | |
Apr 18, 2025 06:56:12.681391001 CEST | 1358 | IN | |
Apr 18, 2025 06:56:12.681407928 CEST | 1358 | IN | |
Apr 18, 2025 06:56:12.681427002 CEST | 1358 | IN | |
Apr 18, 2025 06:56:12.681446075 CEST | 1358 | IN | |
Apr 18, 2025 06:56:12.938322067 CEST | 1358 | IN | |
Apr 18, 2025 06:56:14.155771017 CEST | 340 | OUT | |
Apr 18, 2025 06:56:14.413861990 CEST | 321 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.24 | 60827 | 104.21.20.196 | 443 | 7056 | C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-18 04:56:08 UTC | 320 | OUT | |
2025-04-18 04:56:08 UTC | 482 | IN | |
2025-04-18 04:56:08 UTC | 13 | IN | |
2025-04-18 04:56:08 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.24 | 60828 | 104.21.20.196 | 443 | 7056 | C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-18 04:56:09 UTC | 223 | OUT | |
2025-04-18 04:56:09 UTC | 482 | IN | |
2025-04-18 04:56:09 UTC | 13 | IN | |
2025-04-18 04:56:09 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.24 | 60829 | 104.21.20.196 | 443 | 7056 | C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-18 04:56:10 UTC | 305 | OUT | |
2025-04-18 04:56:10 UTC | 664 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.24 | 60832 | 104.21.20.196 | 443 | 7056 | C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-18 04:56:11 UTC | 185 | OUT | |
2025-04-18 04:56:12 UTC | 664 | IN | |
2025-04-18 04:56:12 UTC | 198 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.24 | 60838 | 104.21.20.196 | 443 | 7056 | C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-18 04:56:13 UTC | 208 | OUT | |
2025-04-18 04:56:14 UTC | 664 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Target ID: | 0 |
Start time: | 00:56:03 |
Start date: | 18/04/2025 |
Path: | C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff79de30000 |
File size: | 1'637'952 bytes |
MD5 hash: | A9F0EC89897AC6C878D217DFB64CA752 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | moderate |
Has exited: | false |