Windows
Analysis Report
RFQ No. M109241 22.04.2025.xlsx
Overview
General Information
Detection
Score: | 64 |
Range: | 0 - 100 |
Confidence: | 100% |
Signatures
Classification
- System is w11x64_office
EXCEL.EXE (PID: 7400 cmdline:
"C:\Progra m Files\Mi crosoft Of fice\Root\ Office16\E XCEL.EXE" /automatio n -Embeddi ng MD5: F9F7B6C42211B06E7AC3E4B60AA8FB77) splwow64.exe (PID: 8432 cmdline:
C:\Windows \splwow64. exe 12288 MD5: AF4A7EBF6114EE9E6FBCC910EC3C96E6)
appidpolicyconverter.exe (PID: 1260 cmdline:
"C:\Window s\system32 \appidpoli cyconverte r.exe" MD5: 6567D9CF2545FAAC60974D9D682700D4) conhost.exe (PID: 6696 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 9698384842DA735D80D278A427A229AB)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
INDICATOR_XML_LegacyDrawing_AutoLoad_Document | detects AutoLoad documents using LegacyDrawing | ditekSHen |
|
System Summary |
---|
Source: | Author: Christopher Peacock '@securepeacock', SCYTHE '@scythe_io', Florian Roth '@Neo23x0", Tim Shelton: |
Source: | Author: X__Junior (Nextron Systems): |
- • AV Detection
- • Compliance
- • Software Vulnerabilities
- • Networking
- • System Summary
- • Hooking and other Techniques for Hiding and Protection
- • Malware Analysis System Evasion
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | Virustotal: | Perma Link | ||
Source: | ReversingLabs: |
Source: | Directory created: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | DNS query: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | IP Address: |
Source: | JA3 fingerprint: |
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: |
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
System Summary |
---|
Source: | Matched rule: |
Source: | Matched rule: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | OLE indicator, Workbook stream: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Virustotal: | ||
Source: | ReversingLabs: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Window detected: |
Source: | Key opened: | Jump to behavior |
Source: | Directory created: | Jump to behavior |
Source: | Static file information: |
Source: | File opened: | Jump to behavior |
Source: | Initial sample: |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Source: | Window / User API: | Jump to behavior |
Source: | Last function: | ||
Source: | Last function: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Process information queried: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 3 Exploitation for Client Execution | 1 DLL Side-Loading | 1 Process Injection | 3 Masquerading | OS Credential Dumping | 1 Process Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 DLL Side-Loading | 1 Virtualization/Sandbox Evasion | LSASS Memory | 1 Virtualization/Sandbox Evasion | Remote Desktop Protocol | Data from Removable Media | 1 Ingress Tool Transfer | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 1 Process Injection | Security Account Manager | 1 Application Window Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | 2 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 DLL Side-Loading | NTDS | 1 File and Directory Discovery | Distributed Component Object Model | Input Capture | 3 Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | Software Packing | LSA Secrets | 2 System Information Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
53% | Virustotal | Browse | ||
72% | ReversingLabs | Document-Office.Exploit.CVE-2017-11882 | ||
100% | Avira | EXP/CVE-2017-11882.Gen |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
bg.microsoft.map.fastly.net | 199.232.210.172 | true | false | high | |
a726.dscd.akamai.net | 23.209.84.82 | true | false | high | |
s-0005.dual-s-msedge.net | 52.123.129.14 | true | false | high | |
s-part-0043.t-0009.t-msedge.net | 13.107.246.71 | true | false | high | |
otelrules.svc.static.microsoft | unknown | unknown | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high | ||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
13.107.246.71 | s-part-0043.t-0009.t-msedge.net | United States | 8068 | MICROSOFT-CORP-MSN-AS-BLOCKUS | false |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1671005 |
Start date and time: | 2025-04-22 13:44:43 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 11s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowsofficecookbook.jbs |
Analysis system description: | Windows 11 23H2 with Office Professional Plus 2021, Chrome 131, Firefox 133, Adobe Reader DC 24, Java 8 Update 431, 7zip 24.09 |
Run name: | Potential for more IOCs and behavior |
Number of analysed new started processes analysed: | 20 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | RFQ No. M109241 22.04.2025.xlsx |
Detection: | MAL |
Classification: | mal64.winXLSX@5/6@1/1 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis
(whitelisted): MpCmdRun.exe, d llhost.exe, sppsvc.exe, SIHCli ent.exe, conhost.exe, appidcer tstorecheck.exe, svchost.exe - Excluded IPs from analysis (wh
itelisted): 52.109.8.89, 52.10 9.0.140, 52.109.0.142, 23.220. 73.6, 23.220.73.19, 13.89.179. 9, 52.123.129.14, 23.209.84.82 , 20.190.151.67, 4.175.87.197, 184.29.183.29 - Excluded domains from analysis
(whitelisted): odc.officeapps .live.com, slscr.update.micros oft.com, osiprod-wus-bronze-az sc-000.westus.cloudapp.azure.c om, cus-config.officeapps.live .com, res-1.cdn.office.net, a7 67.dspw65.akamai.net, osiprod- wus-buff-azsc-000.westus.cloud app.azure.com, mobile.events.d ata.microsoft.com, roaming.off iceapps.live.com, onedscolprdc us09.centralus.cloudapp.azure. com, wus-azsc-000.roaming.offi ceapps.live.com, dual-s-0005-o ffice.config.skype.com, login. live.com, officeclient.microso ft.com, c.pki.goog, wu-b-net.t rafficmanager.net, wus-azsc-00 0.odc.officeapps.live.com, ecs .office.com, fs.microsoft.com, ctldl.windowsupdate.com.deliv ery.microsoft.com, prod.config svc1.live.com.akadns.net, us2. roaming1.live.com.akadns.net, ctldl.windowsupdate.com, prod. roaming1.live.com.akadns.net, res-stls-prod.edgesuite.net, f e3cr.delivery.mp.microsoft.com , download.windowsupdate.com.e dgesuite.net, us2.odcsm1.live. com.akadns.net, res-prod.traff icmanager.net, config.officeap ps.live.com, us.configsvc1.liv e.co - Not all processes where analyz
ed, report is missing behavior information - Report size getting too big, t
oo many NtCreateKey calls foun d. - Report size getting too big, t
oo many NtQueryValueKey calls found. - Report size getting too big, t
oo many NtReadVirtualMemory ca lls found. - Report size getting too big, t
oo many NtSetValueKey calls fo und.
Time | Type | Description |
---|---|---|
07:46:49 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
13.107.246.71 | Get hash | malicious | Tycoon2FA | Browse | ||
Get hash | malicious | CAPTCHA Scam ClickFix | Browse | |||
Get hash | malicious | Invisible JS, Tycoon2FA | Browse | |||
Get hash | malicious | Invisible JS, Tycoon2FA | Browse | |||
Get hash | malicious | HTMLPhisher | Browse | |||
Get hash | malicious | HTMLPhisher | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
a726.dscd.akamai.net | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher, Invisible JS, Tycoon2FA | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
s-0005.dual-s-msedge.net | Get hash | malicious | GuLoader | Browse |
| |
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | LockBit ransomware | Browse |
| ||
Get hash | malicious | LockBit ransomware | Browse |
| ||
Get hash | malicious | GuLoader | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | GuLoader | Browse |
| ||
Get hash | malicious | GuLoader | Browse |
| ||
Get hash | malicious | GuLoader | Browse |
| ||
bg.microsoft.map.fastly.net | Get hash | malicious | LummaC Stealer | Browse |
| |
Get hash | malicious | LummaC Stealer | Browse |
| ||
Get hash | malicious | AsyncRAT, PureLog Stealer, zgRAT | Browse |
| ||
Get hash | malicious | HTMLPhisher, Invisible JS, Tycoon2FA | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | LockBit ransomware | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | AsyncRAT, DcRat | Browse |
| ||
Get hash | malicious | Amadey, LockBit ransomware, LummaC Stealer, Vidar | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
MICROSOFT-CORP-MSN-AS-BLOCKUS | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Tycoon2FA | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
258a5a1e95b8a911872bae9081526644 | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Process: | C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 118 |
Entropy (8bit): | 3.5700810731231707 |
Encrypted: | false |
SSDEEP: | 3:QaklTlAlXMLLmHlIlFLlmIK/5lTn84vlJlhlXlDHlA6l3l6Als:QFulcLk04/5p8GVz6QRq |
MD5: | 573220372DA4ED487441611079B623CD |
SHA1: | 8F9D967AC6EF34640F1F0845214FBC6994C0CB80 |
SHA-256: | BE84B842025E4241BFE0C9F7B8F86A322E4396D893EF87EA1E29C74F47B6A22D |
SHA-512: | F19FA3583668C3AF92A9CEF7010BD6ECEC7285F9C8665F2E9528DBA606F105D9AF9B1DB0CF6E7F77EF2E395943DC0D5CB37149E773319078688979E4024F9DD7 |
Malicious: | false |
Reputation: | high, very likely benign file |
Preview: |
Process: | C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 20971520 |
Entropy (8bit): | 8.112143835430977E-5 |
Encrypted: | false |
SSDEEP: | 3:Tuekk9NJtHFfs1XsExe/t:qeVJ8 |
MD5: | AFDEAC461EEC32D754D8E6017E845D21 |
SHA1: | 5D0874C19B70638A0737696AEEE55BFCC80D7ED8 |
SHA-256: | 3A96B02F6A09F6A6FAC2A44A5842FF9AEB17EB4D633E48ABF6ADDF6FB447C7E2 |
SHA-512: | CAB6B8F9FFDBD80210F42219BAC8F1124D6C0B6995C5128995F7F48CED8EF0F2159EA06A2CD09B1FDCD409719F94A7DB437C708D3B1FDA01FDC80141A4595FC7 |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
Process: | C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 20971520 |
Entropy (8bit): | 0.0 |
Encrypted: | false |
SSDEEP: | 3:: |
MD5: | 8F4E33F3DC3E414FF94E5FB6905CBA8C |
SHA1: | 9674344C90C2F0646F0B78026E127C9B86E3AD77 |
SHA-256: | CD52D81E25F372E6FA4DB2C0DFCEB59862C1969CAB17096DA352B34950C973CC |
SHA-512: | 7FB91E868F3923BBD043725818EF3A5D8D08EBF1059A18AC0FE07040D32EEBA517DA11515E6A4AFAEB29BCC5E0F1543BA2C595B0FE8E6167DDC5E6793EDEF5BB |
Malicious: | false |
Reputation: | high, very likely benign file |
Preview: |
Process: | C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 20971520 |
Entropy (8bit): | 0.20911885431298294 |
Encrypted: | false |
SSDEEP: | 1536:rfAgEKXhrDwSHuxiZHqaO0gqj3lEB8dvATyfCHvHO0syCNVgu92/qUkfRYb6ETMi:cg7MCuxwqego28FEOo204WBkU |
MD5: | 6D412BD91937BD3006EEA9F3901572A4 |
SHA1: | A54C4FD53C75844C59EECE4A2EF34517B2106458 |
SHA-256: | F5998E21DBCB3706FEB87FE24C47657A6E4633CFFF8D4265F51089D5C877D2C5 |
SHA-512: | 6A6E55E17ACA25EE5A50774247B9CC37BDACDA93CFA4A0E924266EDC40D1FC10467EC141FF4D4C850727F078F1CCB35F67C2D37BEC597B9E9682335D911B969E |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 20971520 |
Entropy (8bit): | 0.0 |
Encrypted: | false |
SSDEEP: | 3:: |
MD5: | 8F4E33F3DC3E414FF94E5FB6905CBA8C |
SHA1: | 9674344C90C2F0646F0B78026E127C9B86E3AD77 |
SHA-256: | CD52D81E25F372E6FA4DB2C0DFCEB59862C1969CAB17096DA352B34950C973CC |
SHA-512: | 7FB91E868F3923BBD043725818EF3A5D8D08EBF1059A18AC0FE07040D32EEBA517DA11515E6A4AFAEB29BCC5E0F1543BA2C595B0FE8E6167DDC5E6793EDEF5BB |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 165 |
Entropy (8bit): | 1.4377382811115937 |
Encrypted: | false |
SSDEEP: | 3:EVANFN:EqfN |
MD5: | 359140EB88A757E2BBEF2F7D32DCC4E5 |
SHA1: | FD16035441ADF907BBFC594A96470C202E265067 |
SHA-256: | 42CDE461F058A0C6F6C5A69BD1D21114CD55929011C77BCB9A025B9CA43ED71F |
SHA-512: | 9ADF6AC24E55AA161D2FFA1AC3BBBF03A7028DEFD8E1722FA52CAF7C730F7CF8AAE2073A50FD8AA004AF46E9A578A3B8088DD89415368E64E1916367CE126741 |
Malicious: | true |
Preview: |
File type: | |
Entropy (8bit): | 7.9984457209168305 |
TrID: |
|
File name: | RFQ No. M109241 22.04.2025.xlsx |
File size: | 1'491'125 bytes |
MD5: | 607bc92c894b4d8f1e3519488e5af69e |
SHA1: | 9aef9d5bdc07d8266900d2efd2378a2b79a144e8 |
SHA256: | 5b6787d5068199e43006b0918523a3685d9962f5c0a75113656051b3aa74b360 |
SHA512: | b507700f4d1e915ff77eb569de3dd1c077a7d9faa4a8ba89cfe6e06a54ca39738da3e60a82f268fc3681661181986daf3d4efb03fa0ad91b77d090fdca1947ef |
SSDEEP: | 24576:MIvloKGKtkgWkGKlFS81+C6oV304bmIVeEcMi0V96ZNoUmn3Rma:PoQ2+tVSmc6V9EoNma |
TLSH: | 376533527F32163D3AEABB051F1D9C93AEFBCD900C2A9746D53013A32546B56B093F18 |
File Content Preview: | PK........LB.Z.hD~....e.......[Content_Types].xmlUT....P.h.P.h.P.h.U[K.0.~...%..f.(".>8}.....&g[\...8...I.&.+.....$..|'....2..B...l..Y.V:...`......"...q.........F/k.1#....#.K...C%b.<X...P...0.^........\:.`....]...@...'..AT..W.#.A...........&.7Z.$.|i.....N |
Icon Hash: | 35e58a8c0c8a85b9 |
Document Type: | OpenXML |
Number of OLE Files: | 1 |
Has Summary Info: | |
Application Name: | |
Encrypted Document: | False |
Contains Word Document Stream: | False |
Contains Workbook/Book Stream: | True |
Contains PowerPoint Document Stream: | False |
Contains Visio Document Stream: | False |
Contains ObjectPool Stream: | False |
Flash Objects Count: | 0 |
Contains VBA Macros: | False |
Author: | |
Last Saved By: | |
Create Time: | 2022-11-18T02:05:27Z |
Last Saved Time: | 2022-11-18T02:07:12Z |
Creating Application: | |
Security: | 0 |
Thumbnail Scaling Desired: | false |
Contains Dirty Links: | false |
Shared Document: | false |
Changed Hyperlinks: | false |
Application Version: | 12.0000 |
General | |
Stream Path: | \x1oLe10natIve |
CLSID: | |
File Type: | data |
Stream Size: | 1708665 |
Entropy: | 7.470485087539536 |
Base64 Encoded: | True |
Data ASCII: | f j . . H . , . . v } u - W / . ) 6 % @ - . ? . U . o . . . * . 2 D . P @ } . & . . m R . } . A . V . . \\ $ . . f 9 . . . . . t R h U W . ) n e . 8 t _ I & d x [ d . . ; . W 5 [ x . W R & . + { O . . e 7 ? ( 1 P p 6 = ] & . Y 4 . f G 1 Y r . . B . . . . N i U j . . a 1 T . 4 E G % . V S . . * S & 8 ` . k R . 7 O - t 7 . . S . 6 . z 0 F v . I ; Z } d x Q V w < a W S | E X 7 X . ) < . . f , . % X C H f o { Z ] . . . . } . u . . J 9 2 m . R Y 5 . R X x . . 4 r L . 9 . r + " + w . > . _ H 7 . . ) . . M . 6 . . |
Data Raw: | 66 8d 6a 05 02 c7 48 19 2c ea 01 08 76 94 b8 93 7d 75 a1 2d 57 c0 2f a1 8b 08 8b 29 b8 cc 36 25 40 2d 1c cf de 3f 8b 10 55 ff d2 05 f1 e6 6f 1e 05 1f 2a 9c e1 ff e0 96 bb 08 32 80 44 00 50 40 7d 19 26 f3 14 dd db 7f 96 ad 6d f4 52 1b 7d e2 bb 93 d5 cd 41 c1 df 18 97 56 c1 bf bd 19 db a6 a3 5c 24 ba ef 92 18 f5 08 ab eb 66 39 01 1c 91 1b f3 ec aa b7 05 9a c2 df 74 52 68 55 57 19 fc |
General | |
Stream Path: | SjX9OrXEG |
CLSID: | |
File Type: | empty |
Stream Size: | 0 |
Entropy: | 0.0 |
Base64 Encoded: | False |
Data ASCII: | |
Data Raw: |
Download Network PCAP: filtered – full
- Total Packets: 20
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Apr 22, 2025 13:46:54.958452940 CEST | 49698 | 443 | 192.168.2.25 | 13.107.246.71 |
Apr 22, 2025 13:46:54.958487034 CEST | 443 | 49698 | 13.107.246.71 | 192.168.2.25 |
Apr 22, 2025 13:46:54.958650112 CEST | 49698 | 443 | 192.168.2.25 | 13.107.246.71 |
Apr 22, 2025 13:46:54.958735943 CEST | 49699 | 443 | 192.168.2.25 | 13.107.246.71 |
Apr 22, 2025 13:46:54.958779097 CEST | 443 | 49699 | 13.107.246.71 | 192.168.2.25 |
Apr 22, 2025 13:46:54.958929062 CEST | 49699 | 443 | 192.168.2.25 | 13.107.246.71 |
Apr 22, 2025 13:46:54.959116936 CEST | 49698 | 443 | 192.168.2.25 | 13.107.246.71 |
Apr 22, 2025 13:46:54.959135056 CEST | 443 | 49698 | 13.107.246.71 | 192.168.2.25 |
Apr 22, 2025 13:46:54.959166050 CEST | 49699 | 443 | 192.168.2.25 | 13.107.246.71 |
Apr 22, 2025 13:46:54.959181070 CEST | 443 | 49699 | 13.107.246.71 | 192.168.2.25 |
Apr 22, 2025 13:46:55.394579887 CEST | 443 | 49698 | 13.107.246.71 | 192.168.2.25 |
Apr 22, 2025 13:46:55.394701958 CEST | 49698 | 443 | 192.168.2.25 | 13.107.246.71 |
Apr 22, 2025 13:46:55.398351908 CEST | 49698 | 443 | 192.168.2.25 | 13.107.246.71 |
Apr 22, 2025 13:46:55.398374081 CEST | 443 | 49698 | 13.107.246.71 | 192.168.2.25 |
Apr 22, 2025 13:46:55.398562908 CEST | 443 | 49699 | 13.107.246.71 | 192.168.2.25 |
Apr 22, 2025 13:46:55.398633957 CEST | 443 | 49698 | 13.107.246.71 | 192.168.2.25 |
Apr 22, 2025 13:46:55.398680925 CEST | 49699 | 443 | 192.168.2.25 | 13.107.246.71 |
Apr 22, 2025 13:46:55.400796890 CEST | 49699 | 443 | 192.168.2.25 | 13.107.246.71 |
Apr 22, 2025 13:46:55.400806904 CEST | 443 | 49699 | 13.107.246.71 | 192.168.2.25 |
Apr 22, 2025 13:46:55.401036024 CEST | 443 | 49699 | 13.107.246.71 | 192.168.2.25 |
Apr 22, 2025 13:46:55.408117056 CEST | 49699 | 443 | 192.168.2.25 | 13.107.246.71 |
Apr 22, 2025 13:46:55.408119917 CEST | 49698 | 443 | 192.168.2.25 | 13.107.246.71 |
Apr 22, 2025 13:46:55.452270031 CEST | 443 | 49698 | 13.107.246.71 | 192.168.2.25 |
Apr 22, 2025 13:46:55.452289104 CEST | 443 | 49699 | 13.107.246.71 | 192.168.2.25 |
Apr 22, 2025 13:46:55.673738956 CEST | 443 | 49698 | 13.107.246.71 | 192.168.2.25 |
Apr 22, 2025 13:46:55.673767090 CEST | 443 | 49698 | 13.107.246.71 | 192.168.2.25 |
Apr 22, 2025 13:46:55.673823118 CEST | 49698 | 443 | 192.168.2.25 | 13.107.246.71 |
Apr 22, 2025 13:46:55.673852921 CEST | 443 | 49698 | 13.107.246.71 | 192.168.2.25 |
Apr 22, 2025 13:46:55.673871040 CEST | 443 | 49698 | 13.107.246.71 | 192.168.2.25 |
Apr 22, 2025 13:46:55.673919916 CEST | 49698 | 443 | 192.168.2.25 | 13.107.246.71 |
Apr 22, 2025 13:46:55.674897909 CEST | 49698 | 443 | 192.168.2.25 | 13.107.246.71 |
Apr 22, 2025 13:46:55.674926043 CEST | 443 | 49698 | 13.107.246.71 | 192.168.2.25 |
Apr 22, 2025 13:46:55.674947023 CEST | 49698 | 443 | 192.168.2.25 | 13.107.246.71 |
Apr 22, 2025 13:46:55.674953938 CEST | 443 | 49698 | 13.107.246.71 | 192.168.2.25 |
Apr 22, 2025 13:46:55.694953918 CEST | 443 | 49699 | 13.107.246.71 | 192.168.2.25 |
Apr 22, 2025 13:46:55.695271015 CEST | 443 | 49699 | 13.107.246.71 | 192.168.2.25 |
Apr 22, 2025 13:46:55.695317030 CEST | 49699 | 443 | 192.168.2.25 | 13.107.246.71 |
Apr 22, 2025 13:46:55.695450068 CEST | 49699 | 443 | 192.168.2.25 | 13.107.246.71 |
Apr 22, 2025 13:46:55.695467949 CEST | 443 | 49699 | 13.107.246.71 | 192.168.2.25 |
Apr 22, 2025 13:46:55.695478916 CEST | 49699 | 443 | 192.168.2.25 | 13.107.246.71 |
Apr 22, 2025 13:46:55.695485115 CEST | 443 | 49699 | 13.107.246.71 | 192.168.2.25 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Apr 22, 2025 13:46:54.778395891 CEST | 62651 | 53 | 192.168.2.25 | 1.1.1.1 |
Apr 22, 2025 13:46:54.957516909 CEST | 53 | 62651 | 1.1.1.1 | 192.168.2.25 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Apr 22, 2025 13:46:54.778395891 CEST | 192.168.2.25 | 1.1.1.1 | 0x5352 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Apr 22, 2025 13:45:50.728693962 CEST | 1.1.1.1 | 192.168.2.25 | 0x4879 | No error (0) | s-0005.dual-s-msedge.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 22, 2025 13:45:50.728693962 CEST | 1.1.1.1 | 192.168.2.25 | 0x4879 | No error (0) | 52.123.129.14 | A (IP address) | IN (0x0001) | false | ||
Apr 22, 2025 13:45:50.728693962 CEST | 1.1.1.1 | 192.168.2.25 | 0x4879 | No error (0) | 52.123.128.14 | A (IP address) | IN (0x0001) | false | ||
Apr 22, 2025 13:45:51.957933903 CEST | 1.1.1.1 | 192.168.2.25 | 0xf8e1 | No error (0) | a726.dscd.akamai.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 22, 2025 13:45:51.957933903 CEST | 1.1.1.1 | 192.168.2.25 | 0xf8e1 | No error (0) | 23.209.84.82 | A (IP address) | IN (0x0001) | false | ||
Apr 22, 2025 13:45:51.957933903 CEST | 1.1.1.1 | 192.168.2.25 | 0xf8e1 | No error (0) | 23.209.84.19 | A (IP address) | IN (0x0001) | false | ||
Apr 22, 2025 13:46:54.039721966 CEST | 1.1.1.1 | 192.168.2.25 | 0xb0c1 | No error (0) | 199.232.210.172 | A (IP address) | IN (0x0001) | false | ||
Apr 22, 2025 13:46:54.039721966 CEST | 1.1.1.1 | 192.168.2.25 | 0xb0c1 | No error (0) | 199.232.214.172 | A (IP address) | IN (0x0001) | false | ||
Apr 22, 2025 13:46:54.957516909 CEST | 1.1.1.1 | 192.168.2.25 | 0x5352 | No error (0) | otelrules-bzhndjfje8dvh5fd.z01.azurefd.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 22, 2025 13:46:54.957516909 CEST | 1.1.1.1 | 192.168.2.25 | 0x5352 | No error (0) | star-azurefd-prod.trafficmanager.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 22, 2025 13:46:54.957516909 CEST | 1.1.1.1 | 192.168.2.25 | 0x5352 | No error (0) | shed.dual-low.s-part-0043.t-0009.t-msedge.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 22, 2025 13:46:54.957516909 CEST | 1.1.1.1 | 192.168.2.25 | 0x5352 | No error (0) | s-part-0043.t-0009.t-msedge.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 22, 2025 13:46:54.957516909 CEST | 1.1.1.1 | 192.168.2.25 | 0x5352 | No error (0) | 13.107.246.71 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.25 | 49699 | 13.107.246.71 | 443 | 7400 | C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-22 11:46:55 UTC | 214 | OUT | |
2025-04-22 11:46:55 UTC | 491 | IN | |
2025-04-22 11:46:55 UTC | 461 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.25 | 49698 | 13.107.246.71 | 443 | 7400 | C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-22 11:46:55 UTC | 215 | OUT | |
2025-04-22 11:46:55 UTC | 515 | IN | |
2025-04-22 11:46:55 UTC | 2781 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 07:45:45 |
Start date: | 22/04/2025 |
Path: | C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff70a000000 |
File size: | 70'082'712 bytes |
MD5 hash: | F9F7B6C42211B06E7AC3E4B60AA8FB77 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | moderate |
Has exited: | false |
Target ID: | 6 |
Start time: | 07:45:58 |
Start date: | 22/04/2025 |
Path: | C:\Windows\System32\appidpolicyconverter.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6a4810000 |
File size: | 155'648 bytes |
MD5 hash: | 6567D9CF2545FAAC60974D9D682700D4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | moderate |
Has exited: | true |
Target ID: | 7 |
Start time: | 07:45:58 |
Start date: | 22/04/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff729690000 |
File size: | 1'040'384 bytes |
MD5 hash: | 9698384842DA735D80D278A427A229AB |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | moderate |
Has exited: | true |
Target ID: | 12 |
Start time: | 07:46:49 |
Start date: | 22/04/2025 |
Path: | C:\Windows\splwow64.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff75e4e0000 |
File size: | 192'512 bytes |
MD5 hash: | AF4A7EBF6114EE9E6FBCC910EC3C96E6 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | moderate |
Has exited: | false |