Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
REMIT_20241001_001.csv

Overview

General Information

Sample name:REMIT_20241001_001.csv
Analysis ID:1523639
MD5:c045dcd260c51ec69f8150693a98fe99
SHA1:c7b50c573ddf44d305cc25f0b222129d69e6328a
SHA256:b2a448e60df6cd9734bc261defe1954d683079ba35b21580702b507e16d65da5
Infos:

Detection

Score:3
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
Sample execution stops while process was sleeping (likely an evasion)
Sigma detected: Excel Network Connections
Sigma detected: Suspicious Office Outbound Connections

Classification

  • System is w10x64
  • EXCEL.EXE (PID: 6872 cmdline: "C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" /automation -Embedding MD5: 4A871771235598812032C822E6F68F19)
    • splwow64.exe (PID: 7152 cmdline: C:\Windows\splwow64.exe 12288 MD5: 77DE7761B037061C7C112FD3C5B91E73)
  • cleanup
No configs have been found
No yara matches
Source: Network ConnectionAuthor: Christopher Peacock '@securepeacock', SCYTHE '@scythe_io', Florian Roth '@Neo23x0", Tim Shelton: Data: DestinationIp: 13.107.246.60, DestinationIsIpv6: false, DestinationPort: 443, EventID: 3, Image: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE, Initiated: true, ProcessId: 6872, Protocol: tcp, SourceIp: 192.168.2.4, SourceIsIpv6: false, SourcePort: 49753
Source: Network ConnectionAuthor: X__Junior (Nextron Systems): Data: DestinationIp: 192.168.2.4, DestinationIsIpv6: false, DestinationPort: 49753, EventID: 3, Image: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE, Initiated: true, ProcessId: 6872, Protocol: tcp, SourceIp: 13.107.246.60, SourceIsIpv6: false, SourcePort: 443
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile opened: C:\Program Files (x86)\Microsoft Office\root\vfs\SystemX86\MSVCR100.dllJump to behavior
Source: unknownHTTPS traffic detected: 13.107.246.60:443 -> 192.168.2.4:49756 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.107.246.60:443 -> 192.168.2.4:49757 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.107.246.60:443 -> 192.168.2.4:49754 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.107.246.60:443 -> 192.168.2.4:49755 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.107.246.60:443 -> 192.168.2.4:49753 version: TLS 1.2
Source: Joe Sandbox ViewIP Address: 13.107.246.60 13.107.246.60
Source: Joe Sandbox ViewJA3 fingerprint: a0e9f5d64349fb13191bc781f81f42e1
Source: global trafficHTTP traffic detected: GET /rules/rule324001v4s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Excel 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule490016v3s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Excel 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule170012v12s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Excel 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule63067v4s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Excel 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule170022v2s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Excel 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule324002v5s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Excel 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule324003v5s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Excel 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule324004v4s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Excel 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule324005v2s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Excel 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule324006v2s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Excel 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: 57C8EDB95DF3F0AD4EE2DC2B8CFD4157.0.drString found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49755
Source: unknownNetwork traffic detected: HTTP traffic on port 49757 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49754
Source: unknownNetwork traffic detected: HTTP traffic on port 49758 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49753
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49762
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49761
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49760
Source: unknownNetwork traffic detected: HTTP traffic on port 49761 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49760 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49762 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49754 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49759
Source: unknownNetwork traffic detected: HTTP traffic on port 49759 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49758
Source: unknownNetwork traffic detected: HTTP traffic on port 49753 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49757
Source: unknownNetwork traffic detected: HTTP traffic on port 49755 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49756 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49756
Source: unknownHTTPS traffic detected: 13.107.246.60:443 -> 192.168.2.4:49756 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.107.246.60:443 -> 192.168.2.4:49757 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.107.246.60:443 -> 192.168.2.4:49754 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.107.246.60:443 -> 192.168.2.4:49755 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.107.246.60:443 -> 192.168.2.4:49753 version: TLS 1.2
Source: classification engineClassification label: clean3.winCSV@3/2@0/1
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile created: C:\Program Files (x86)\Microsoft Office\root\vfs\Common AppData\Microsoft\Office\Heartbeat\HeartbeatCache.xmlJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\mso9C46.tmpJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Temp\{0F9BD8E7-6893-4781-8EAF-33E70EDDF7E5} - OProcSessId.datJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile read: C:\Users\desktop.iniJump to behavior
Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" /automation -Embedding
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288Jump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\CommonJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile opened: C:\Program Files (x86)\Microsoft Office\root\vfs\SystemX86\MSVCR100.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeWindow / User API: threadDelayed 892Jump to behavior
Source: C:\Windows\splwow64.exeLast function: Thread delayed
Source: C:\Windows\splwow64.exeLast function: Thread delayed
Source: C:\Windows\splwow64.exeThread delayed: delay time: 120000Jump to behavior
Source: C:\Windows\splwow64.exeThread delayed: delay time: 120000Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information queried: ProcessInformationJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential Dumping1
Process Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Virtualization/Sandbox Evasion
LSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
Process Injection
Security Account Manager1
Application Window Discovery
SMB/Windows Admin SharesData from Network Shared Drive2
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDS1
File and Directory Discovery
Distributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon ScriptSoftware PackingLSA Secrets1
System Information Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
s-part-0032.t-0009.t-msedge.net
13.107.246.60
truefalse
    unknown
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    13.107.246.60
    s-part-0032.t-0009.t-msedge.netUnited States
    8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
    Joe Sandbox version:41.0.0 Charoite
    Analysis ID:1523639
    Start date and time:2024-10-01 21:51:08 +02:00
    Joe Sandbox product:CloudBasic
    Overall analysis duration:0h 4m 12s
    Hypervisor based Inspection enabled:false
    Report type:full
    Cookbook file name:default.jbs
    Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
    Number of analysed new started processes analysed:8
    Number of new started drivers analysed:0
    Number of existing processes analysed:0
    Number of existing drivers analysed:0
    Number of injected processes analysed:0
    Technologies:
    • HCA enabled
    • EGA enabled
    • AMSI enabled
    Analysis Mode:default
    Analysis stop reason:Timeout
    Sample name:REMIT_20241001_001.csv
    Detection:CLEAN
    Classification:clean3.winCSV@3/2@0/1
    EGA Information:Failed
    HCA Information:
    • Successful, ratio: 100%
    • Number of executed functions: 0
    • Number of non-executed functions: 0
    Cookbook Comments:
    • Found application associated with file extension: .csv
    • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
    • Excluded IPs from analysis (whitelisted): 52.109.89.18, 184.28.90.27, 52.113.194.132, 52.109.76.243, 2.19.126.163, 2.19.126.137, 20.189.173.12
    • Excluded domains from analysis (whitelisted): onedscolprdwus11.westus.cloudapp.azure.com, slscr.update.microsoft.com, otelrules.afd.azureedge.net, weu-azsc-config.officeapps.live.com, a767.dspw65.akamai.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, eur.roaming1.live.com.akadns.net, neu-azsc-000.roaming.officeapps.live.com, ecs-office.s-0005.s-msedge.net, roaming.officeapps.live.com, ocsp.digicert.com, login.live.com, e16604.g.akamaiedge.net, officeclient.microsoft.com, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, ecs.office.com, self-events-data.trafficmanager.net, fs.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, otelrules.azureedge.net, prod.configsvc1.live.com.akadns.net, self.events.data.microsoft.com, ctldl.windowsupdate.com, prod.roaming1.live.com.akadns.net, s-0005-office.config.skype.com, fe3cr.delivery.mp.microsoft.com, download.windowsupdate.com.edgesuite.net, s-0005.s-msedge.net, config.officeapps.live.com
    • Not all processes where analyzed, report is missing behavior information
    • Report size getting too big, too many NtCreateKey calls found.
    • Report size getting too big, too many NtQueryAttributesFile calls found.
    • Report size getting too big, too many NtQueryValueKey calls found.
    • Report size getting too big, too many NtReadVirtualMemory calls found.
    • VT rate limit hit for: REMIT_20241001_001.csv
    TimeTypeDescription
    15:53:03API Interceptor935x Sleep call for process: splwow64.exe modified
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    13.107.246.60https://protect-us.mimecast.com/s/wFHoCqxrAnt7V914iZaD1vGet hashmaliciousUnknownBrowse
    • www.mimecast.com/Customers/Support/Contact-support/
    http://wellsfargo.dealogic.com/clientportal/Conferences/Registration/Form/368?menuItemId=5Get hashmaliciousUnknownBrowse
    • wellsfargo.dealogic.com/clientportal/Conferences/Registration/Form/368?menuItemId=5
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    s-part-0032.t-0009.t-msedge.netELECTRONIC RECEIPT_Opcsa.htmlGet hashmaliciousEvilProxy, HTMLPhisherBrowse
    • 13.107.246.60
    https://pt9w4x.nauleacepr.com/9QLzRhIr/#Ygovernment.relations@rolls-royce.comGet hashmaliciousHTMLPhisherBrowse
    • 13.107.246.60
    https://app.powerbi.com/Redirect?action=OpenLink&linkId=zdvBDOlnbh&ctid=fc5c5a9f-3ade-48e2-abb1-5450e9fb332d&pbi_source=linkShare_m365Notify&bookmarkGuid=5672cb10-cc42-4d8a-943e-29b95931de59&bookmarkUsage=1Get hashmaliciousHTMLPhisherBrowse
    • 13.107.246.60
    Swift_ach Complaints.sppgCQDM.htmlGet hashmaliciousHTMLPhisherBrowse
    • 13.107.246.60
    1_13904442253.xla.xlsxGet hashmaliciousUnknownBrowse
    • 13.107.246.60
    http://customervoice.microsoft.com/Pages/ResponsePage.aspx?id=rCxHFZLdZUGNvhn9cgWChLhuCDtpfZJDs2F6orjCzx1UQTZXSUlaNE5INzZVSkgxRlBKR1RMSTVRTi4uGet hashmaliciousHTMLPhisherBrowse
    • 13.107.246.60
    phish_alert_sp2_2.0.0.0.emlGet hashmaliciousUnknownBrowse
    • 13.107.246.60
    https://targetemissionservices.ezofficeinventory.com/users/sign_inGet hashmaliciousUnknownBrowse
    • 13.107.246.60
    https://myworkspace183015a0ec.myclickfunnels.com/reviewdoc--96b32?preview=trueGet hashmaliciousUnknownBrowse
    • 13.107.246.60
    INVOICE DUE..xlsxGet hashmaliciousHTMLPhisherBrowse
    • 13.107.246.60
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    MICROSOFT-CORP-MSN-AS-BLOCKUSSeeking Assistance for Legal Assistance in a Medical Matter.msgGet hashmaliciousUnknownBrowse
    • 51.132.193.105
    https://okefeokok.live/Get hashmaliciousUnknownBrowse
    • 40.81.24.3
    moba-24.2-installer_M64ZB-1.exeGet hashmaliciousPureLog StealerBrowse
    • 204.79.197.203
    Audio_Msg..00299229202324Transcript.htmlGet hashmaliciousUnknownBrowse
    • 150.171.27.10
    moba-24.2-installer_M64ZB-1.exeGet hashmaliciousPureLog StealerBrowse
    • 20.157.119.2
    https://wetransfer.com/downloads/fc718a7028ccd1e273879a61c0883fe420241001145250/8110e2eb5f5a56cc2015d1b3243d9b3120241001145309/33d289?trk=TRN_TDL_01&utm_campaign=TRN_TDL_01&utm_medium=email&utm_source=sendgridGet hashmaliciousHTMLPhisherBrowse
    • 150.171.28.10
    ELECTRONIC RECEIPT_Opcsa.htmlGet hashmaliciousEvilProxy, HTMLPhisherBrowse
    • 13.107.246.60
    test.xlsmGet hashmaliciousUnknownBrowse
    • 13.107.246.45
    Play_VM-Now(Tina.lawvey)CQDM.htmlGet hashmaliciousHTMLPhisherBrowse
    • 13.107.246.44
    https://pt9w4x.nauleacepr.com/9QLzRhIr/#Ygovernment.relations@rolls-royce.comGet hashmaliciousHTMLPhisherBrowse
    • 150.171.27.10
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    a0e9f5d64349fb13191bc781f81f42e1Google_Chrome.exeGet hashmaliciousLummaCBrowse
    • 13.107.246.60
    https://finalstepgetshere.com/uploads/beta111.zipGet hashmaliciousLummaC, Go Injector, LummaC StealerBrowse
    • 13.107.246.60
    file.exeGet hashmaliciousLummaC, Stealc, VidarBrowse
    • 13.107.246.60
    file.exeGet hashmaliciousLummaCBrowse
    • 13.107.246.60
    test.xlsmGet hashmaliciousUnknownBrowse
    • 13.107.246.60
    ZJh3V10O2e.exeGet hashmaliciousLummaCBrowse
    • 13.107.246.60
    ZJh3V10O2e.exeGet hashmaliciousLummaCBrowse
    • 13.107.246.60
    tomarket_app.exeGet hashmaliciousLummaCBrowse
    • 13.107.246.60
    tomarket_app.exeGet hashmaliciousLummaCBrowse
    • 13.107.246.60
    Deolane-Video-PDF.vbsGet hashmaliciousUnknownBrowse
    • 13.107.246.60
    No context
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
    File Type:XML 1.0 document, Unicode text, UTF-16, little-endian text, with CRLF line terminators
    Category:dropped
    Size (bytes):118
    Entropy (8bit):3.5700810731231707
    Encrypted:false
    SSDEEP:3:QaklTlAlXMLLmHlIlFLlmIK/5lTn84vlJlhlXlDHlA6l3l6Als:QFulcLk04/5p8GVz6QRq
    MD5:573220372DA4ED487441611079B623CD
    SHA1:8F9D967AC6EF34640F1F0845214FBC6994C0CB80
    SHA-256:BE84B842025E4241BFE0C9F7B8F86A322E4396D893EF87EA1E29C74F47B6A22D
    SHA-512:F19FA3583668C3AF92A9CEF7010BD6ECEC7285F9C8665F2E9528DBA606F105D9AF9B1DB0CF6E7F77EF2E395943DC0D5CB37149E773319078688979E4024F9DD7
    Malicious:false
    Reputation:moderate, very likely benign file
    Preview:..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".U.T.F.-.1.6.".?.>.....<.H.e.a.r.t.b.e.a.t.C.a.c.h.e./.>.
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
    File Type:data
    Category:dropped
    Size (bytes):338
    Entropy (8bit):3.4459293254020387
    Encrypted:false
    SSDEEP:6:kKbu/Q8AvJFN+SkQlPlEGYRMY9z+s3Ql2DUevat:ju/QxkkPlE99SCQl2DUevat
    MD5:AB274798201A74F1A31126EA6C72C546
    SHA1:061F78FDC7665BF681622C39D22CD816D471E10D
    SHA-256:C9ADA48B4C0CB60D5661243C9FF3EB5032DAC3C8EC6B79E431FA7B8DB9B967D2
    SHA-512:D18A864CB95E8EBEDDB4B56BB18385B63C3A3CCFF03A9FADC394B565DADC12536CC06AE77C7B0E5D340C2F1BB8B3B0C4EB379C709B1B657CFA8D402F35D8A4D7
    Malicious:false
    Reputation:low
    Preview:p...... .........\.b;...(.............................................../.:.@... .........p.........$...............h.t.t.p.:././.c.t.l.d.l...w.i.n.d.o.w.s.u.p.d.a.t.e...c.o.m./.m.s.d.o.w.n.l.o.a.d./.u.p.d.a.t.e./.v.3./.s.t.a.t.i.c./.t.r.u.s.t.e.d.r./.e.n./.d.i.s.a.l.l.o.w.e.d.c.e.r.t.s.t.l...c.a.b...".7.4.6.7.8.7.a.3.f.0.d.9.1.:.0."...
    File type:ASCII text, with CRLF line terminators
    Entropy (8bit):4.712773911372961
    TrID:
      File name:REMIT_20241001_001.csv
      File size:207 bytes
      MD5:c045dcd260c51ec69f8150693a98fe99
      SHA1:c7b50c573ddf44d305cc25f0b222129d69e6328a
      SHA256:b2a448e60df6cd9734bc261defe1954d683079ba35b21580702b507e16d65da5
      SHA512:58b522adcd78bb87daadf91fb91cfc6fd28a5d62a7f1056a11895de0a721ea66130e4d3e4fd558b796d03a1144e0d0bf7a331bb7658f2b17476ed792cdadedb7
      SSDEEP:6:2mgAFxJDIys3CbbxXQ7HRg3/QLVUORtGvn:6AFuIRwRU4LHRu
      TLSH:FBD0C718115E049CDB510151FA7666590C5735A3548C3845F6EAA0F549A1DDB588DD33
      File Content Preview:Reference Number,Date,Amount,Currency,Bank Account Number,Document Reference,Document Date,Amount Due,Amount Paid,Discount Taken..242750000640,10/01/2024,50000,USD,***028,10-2024.1,10/01/2024,50000,50000,0..
      Icon Hash:35e5caacacca85b9
      TimestampSource PortDest PortSource IPDest IP
      Oct 1, 2024 21:53:08.404021025 CEST49753443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:08.404073954 CEST4434975313.107.246.60192.168.2.4
      Oct 1, 2024 21:53:08.404139042 CEST49753443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:08.404220104 CEST49754443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:08.404232979 CEST4434975413.107.246.60192.168.2.4
      Oct 1, 2024 21:53:08.404334068 CEST49754443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:08.404458046 CEST49755443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:08.404488087 CEST4434975513.107.246.60192.168.2.4
      Oct 1, 2024 21:53:08.404531956 CEST49755443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:08.404550076 CEST49753443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:08.404568911 CEST4434975313.107.246.60192.168.2.4
      Oct 1, 2024 21:53:08.404726982 CEST49756443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:08.404752016 CEST4434975613.107.246.60192.168.2.4
      Oct 1, 2024 21:53:08.404805899 CEST49756443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:08.404881001 CEST49757443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:08.404942989 CEST4434975713.107.246.60192.168.2.4
      Oct 1, 2024 21:53:08.405026913 CEST49757443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:08.405214071 CEST49757443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:08.405235052 CEST4434975713.107.246.60192.168.2.4
      Oct 1, 2024 21:53:08.405678988 CEST49754443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:08.405690908 CEST4434975413.107.246.60192.168.2.4
      Oct 1, 2024 21:53:08.405937910 CEST49755443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:08.405951023 CEST4434975513.107.246.60192.168.2.4
      Oct 1, 2024 21:53:08.406167984 CEST49756443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:08.406178951 CEST4434975613.107.246.60192.168.2.4
      Oct 1, 2024 21:53:09.305207014 CEST4434975613.107.246.60192.168.2.4
      Oct 1, 2024 21:53:09.305279016 CEST49756443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:09.305464029 CEST4434975713.107.246.60192.168.2.4
      Oct 1, 2024 21:53:09.305533886 CEST49757443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:09.305826902 CEST4434975413.107.246.60192.168.2.4
      Oct 1, 2024 21:53:09.305871964 CEST4434975513.107.246.60192.168.2.4
      Oct 1, 2024 21:53:09.305907965 CEST49754443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:09.305990934 CEST49755443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:09.308931112 CEST49756443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:09.308942080 CEST4434975613.107.246.60192.168.2.4
      Oct 1, 2024 21:53:09.309190035 CEST4434975613.107.246.60192.168.2.4
      Oct 1, 2024 21:53:09.309812069 CEST4434975313.107.246.60192.168.2.4
      Oct 1, 2024 21:53:09.309870005 CEST49753443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:09.310348034 CEST49757443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:09.310385942 CEST4434975713.107.246.60192.168.2.4
      Oct 1, 2024 21:53:09.310678959 CEST4434975713.107.246.60192.168.2.4
      Oct 1, 2024 21:53:09.311702013 CEST49756443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:09.312560081 CEST49754443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:09.312619925 CEST4434975413.107.246.60192.168.2.4
      Oct 1, 2024 21:53:09.312855959 CEST4434975413.107.246.60192.168.2.4
      Oct 1, 2024 21:53:09.314013958 CEST49757443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:09.315052032 CEST49754443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:09.316323996 CEST49755443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:09.316342115 CEST4434975513.107.246.60192.168.2.4
      Oct 1, 2024 21:53:09.316561937 CEST4434975513.107.246.60192.168.2.4
      Oct 1, 2024 21:53:09.317929983 CEST49755443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:09.319267035 CEST49753443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:09.319294930 CEST4434975313.107.246.60192.168.2.4
      Oct 1, 2024 21:53:09.319580078 CEST4434975313.107.246.60192.168.2.4
      Oct 1, 2024 21:53:09.321449041 CEST49753443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:09.355412960 CEST4434975613.107.246.60192.168.2.4
      Oct 1, 2024 21:53:09.355427980 CEST4434975713.107.246.60192.168.2.4
      Oct 1, 2024 21:53:09.359397888 CEST4434975513.107.246.60192.168.2.4
      Oct 1, 2024 21:53:09.359406948 CEST4434975413.107.246.60192.168.2.4
      Oct 1, 2024 21:53:09.363406897 CEST4434975313.107.246.60192.168.2.4
      Oct 1, 2024 21:53:09.407833099 CEST4434975613.107.246.60192.168.2.4
      Oct 1, 2024 21:53:09.407907009 CEST4434975613.107.246.60192.168.2.4
      Oct 1, 2024 21:53:09.408018112 CEST49756443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:09.412453890 CEST4434975413.107.246.60192.168.2.4
      Oct 1, 2024 21:53:09.412868023 CEST4434975713.107.246.60192.168.2.4
      Oct 1, 2024 21:53:09.412919998 CEST4434975713.107.246.60192.168.2.4
      Oct 1, 2024 21:53:09.412975073 CEST49757443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:09.413311005 CEST4434975413.107.246.60192.168.2.4
      Oct 1, 2024 21:53:09.413366079 CEST49754443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:09.417043924 CEST4434975513.107.246.60192.168.2.4
      Oct 1, 2024 21:53:09.417069912 CEST4434975513.107.246.60192.168.2.4
      Oct 1, 2024 21:53:09.417107105 CEST49755443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:09.417124987 CEST4434975513.107.246.60192.168.2.4
      Oct 1, 2024 21:53:09.417299032 CEST4434975513.107.246.60192.168.2.4
      Oct 1, 2024 21:53:09.417360067 CEST49755443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:09.420114040 CEST4434975313.107.246.60192.168.2.4
      Oct 1, 2024 21:53:09.420167923 CEST4434975313.107.246.60192.168.2.4
      Oct 1, 2024 21:53:09.420226097 CEST49753443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:09.423072100 CEST49754443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:09.423120022 CEST4434975413.107.246.60192.168.2.4
      Oct 1, 2024 21:53:09.423125029 CEST49757443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:09.423125029 CEST49757443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:09.423146009 CEST49754443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:09.423161983 CEST4434975413.107.246.60192.168.2.4
      Oct 1, 2024 21:53:09.423168898 CEST4434975713.107.246.60192.168.2.4
      Oct 1, 2024 21:53:09.423197031 CEST4434975713.107.246.60192.168.2.4
      Oct 1, 2024 21:53:09.423268080 CEST49755443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:09.423268080 CEST49755443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:09.423281908 CEST4434975513.107.246.60192.168.2.4
      Oct 1, 2024 21:53:09.423291922 CEST4434975513.107.246.60192.168.2.4
      Oct 1, 2024 21:53:09.423372030 CEST49756443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:09.423396111 CEST4434975613.107.246.60192.168.2.4
      Oct 1, 2024 21:53:09.426259995 CEST49753443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:09.426259995 CEST49753443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:09.426280975 CEST4434975313.107.246.60192.168.2.4
      Oct 1, 2024 21:53:09.426304102 CEST4434975313.107.246.60192.168.2.4
      Oct 1, 2024 21:53:09.495724916 CEST49759443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:09.495729923 CEST49758443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:09.495771885 CEST4434975913.107.246.60192.168.2.4
      Oct 1, 2024 21:53:09.495790005 CEST4434975813.107.246.60192.168.2.4
      Oct 1, 2024 21:53:09.495873928 CEST49759443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:09.495876074 CEST49758443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:09.496225119 CEST49759443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:09.496228933 CEST49758443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:09.496236086 CEST4434975913.107.246.60192.168.2.4
      Oct 1, 2024 21:53:09.496243000 CEST4434975813.107.246.60192.168.2.4
      Oct 1, 2024 21:53:09.520682096 CEST49760443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:09.520716906 CEST4434976013.107.246.60192.168.2.4
      Oct 1, 2024 21:53:09.522876024 CEST49760443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:09.523320913 CEST49760443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:09.523330927 CEST4434976013.107.246.60192.168.2.4
      Oct 1, 2024 21:53:09.524040937 CEST49761443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:09.524084091 CEST4434976113.107.246.60192.168.2.4
      Oct 1, 2024 21:53:09.524285078 CEST49761443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:09.524487019 CEST49761443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:09.524502039 CEST4434976113.107.246.60192.168.2.4
      Oct 1, 2024 21:53:09.527975082 CEST49762443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:09.527985096 CEST4434976213.107.246.60192.168.2.4
      Oct 1, 2024 21:53:09.528122902 CEST49762443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:09.528305054 CEST49762443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:09.528314114 CEST4434976213.107.246.60192.168.2.4
      Oct 1, 2024 21:53:10.135139942 CEST4434975913.107.246.60192.168.2.4
      Oct 1, 2024 21:53:10.135636091 CEST49759443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:10.135651112 CEST4434975913.107.246.60192.168.2.4
      Oct 1, 2024 21:53:10.137177944 CEST49759443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:10.137181997 CEST4434975913.107.246.60192.168.2.4
      Oct 1, 2024 21:53:10.164882898 CEST4434975813.107.246.60192.168.2.4
      Oct 1, 2024 21:53:10.166299105 CEST49758443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:10.166299105 CEST49758443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:10.166327000 CEST4434975813.107.246.60192.168.2.4
      Oct 1, 2024 21:53:10.166347027 CEST4434975813.107.246.60192.168.2.4
      Oct 1, 2024 21:53:10.169130087 CEST4434976013.107.246.60192.168.2.4
      Oct 1, 2024 21:53:10.169887066 CEST49760443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:10.169894934 CEST4434976013.107.246.60192.168.2.4
      Oct 1, 2024 21:53:10.172394991 CEST4434976113.107.246.60192.168.2.4
      Oct 1, 2024 21:53:10.172426939 CEST49760443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:10.172432899 CEST4434976013.107.246.60192.168.2.4
      Oct 1, 2024 21:53:10.172915936 CEST49761443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:10.172924995 CEST4434976113.107.246.60192.168.2.4
      Oct 1, 2024 21:53:10.173861027 CEST49761443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:10.173866034 CEST4434976113.107.246.60192.168.2.4
      Oct 1, 2024 21:53:10.190604925 CEST4434976213.107.246.60192.168.2.4
      Oct 1, 2024 21:53:10.191025972 CEST49762443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:10.191037893 CEST4434976213.107.246.60192.168.2.4
      Oct 1, 2024 21:53:10.192491055 CEST49762443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:10.192497015 CEST4434976213.107.246.60192.168.2.4
      Oct 1, 2024 21:53:10.235959053 CEST4434975913.107.246.60192.168.2.4
      Oct 1, 2024 21:53:10.236021996 CEST4434975913.107.246.60192.168.2.4
      Oct 1, 2024 21:53:10.236224890 CEST49759443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:10.236310005 CEST49759443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:10.236310005 CEST49759443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:10.236330032 CEST4434975913.107.246.60192.168.2.4
      Oct 1, 2024 21:53:10.236339092 CEST4434975913.107.246.60192.168.2.4
      Oct 1, 2024 21:53:10.270576000 CEST4434975813.107.246.60192.168.2.4
      Oct 1, 2024 21:53:10.270629883 CEST4434975813.107.246.60192.168.2.4
      Oct 1, 2024 21:53:10.270761013 CEST49758443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:10.271126032 CEST49758443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:10.271126032 CEST49758443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:10.271150112 CEST4434975813.107.246.60192.168.2.4
      Oct 1, 2024 21:53:10.271162987 CEST4434975813.107.246.60192.168.2.4
      Oct 1, 2024 21:53:10.271465063 CEST4434976013.107.246.60192.168.2.4
      Oct 1, 2024 21:53:10.271523952 CEST4434976013.107.246.60192.168.2.4
      Oct 1, 2024 21:53:10.271820068 CEST49760443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:10.272092104 CEST49760443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:10.272105932 CEST4434976013.107.246.60192.168.2.4
      Oct 1, 2024 21:53:10.272138119 CEST49760443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:10.272142887 CEST4434976013.107.246.60192.168.2.4
      Oct 1, 2024 21:53:10.275621891 CEST4434976113.107.246.60192.168.2.4
      Oct 1, 2024 21:53:10.275681973 CEST4434976113.107.246.60192.168.2.4
      Oct 1, 2024 21:53:10.278531075 CEST49761443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:10.278619051 CEST49761443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:10.278619051 CEST49761443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:10.278628111 CEST4434976113.107.246.60192.168.2.4
      Oct 1, 2024 21:53:10.278636932 CEST4434976113.107.246.60192.168.2.4
      Oct 1, 2024 21:53:10.503041983 CEST4434976213.107.246.60192.168.2.4
      Oct 1, 2024 21:53:10.503391027 CEST4434976213.107.246.60192.168.2.4
      Oct 1, 2024 21:53:10.503479004 CEST49762443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:10.503556013 CEST49762443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:10.503556013 CEST49762443192.168.2.413.107.246.60
      Oct 1, 2024 21:53:10.503616095 CEST4434976213.107.246.60192.168.2.4
      Oct 1, 2024 21:53:10.503639936 CEST4434976213.107.246.60192.168.2.4
      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
      Oct 1, 2024 21:53:08.403068066 CEST1.1.1.1192.168.2.40xbfb0No error (0)shed.dual-low.s-part-0032.t-0009.t-msedge.nets-part-0032.t-0009.t-msedge.netCNAME (Canonical name)IN (0x0001)false
      Oct 1, 2024 21:53:08.403068066 CEST1.1.1.1192.168.2.40xbfb0No error (0)s-part-0032.t-0009.t-msedge.net13.107.246.60A (IP address)IN (0x0001)false
      • otelrules.azureedge.net
      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      0192.168.2.44975613.107.246.604436872C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
      TimestampBytes transferredDirectionData
      2024-10-01 19:53:09 UTC207OUTGET /rules/rule324001v4s19.xml HTTP/1.1
      Connection: Keep-Alive
      Accept-Encoding: gzip
      User-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Excel 16.0.16827; Pro)
      Host: otelrules.azureedge.net
      2024-10-01 19:53:09 UTC491INHTTP/1.1 200 OK
      Date: Tue, 01 Oct 2024 19:53:09 GMT
      Content-Type: text/xml
      Content-Length: 513
      Connection: close
      Cache-Control: public, max-age=604800, immutable
      Last-Modified: Tue, 09 Apr 2024 00:27:31 GMT
      ETag: "0x8DC582BD84BDCC1"
      x-ms-request-id: 088c1420-201e-0071-50c5-13ff15000000
      x-ms-version: 2018-03-28
      x-azure-ref: 20241001T195309Z-15767c5fc55d6fcl6x6bw8cpdc00000008dg00000000ak7h
      x-fd-int-roxy-purgeid: 0
      X-Cache: TCP_HIT
      X-Cache-Info: L1_T2
      Accept-Ranges: bytes
      2024-10-01 19:53:09 UTC513INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 33 32 34 30 30 31 22 20 56 3d 22 34 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 45 78 74 65 6e 73 69 62 69 6c 69 74 79 2e 56 62 61 54 65 6c 65 6d 65 74 72 79 50 72 6f 6a 65 63 74 4c 6f 61 64 22 20 41 54 54 3d 22 64 62 33 33 34 62 33 30 31 65 37 62 34 37 34 64 62 35 65 30 66 30 32 66 30 37 63 35 31 61 34 37 2d 61 31 62 35 62 63 33 36 2d 31 62 62 65 2d 34 38 32 66 2d 61 36 34 61 2d 63 32 64 39 63 62 36 30 36 37 30 36 2d 37 34 33 39 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 43 61 3d 22 44 43 20 50 53 50 20 50 53 55 22 20 78 6d 6c 6e 73 3d 22
      Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="324001" V="4" DC="SM" EN="Office.Extensibility.VbaTelemetryProjectLoad" ATT="db334b301e7b474db5e0f02f07c51a47-a1b5bc36-1bbe-482f-a64a-c2d9cb606706-7439" SP="CriticalBusinessImpact" DCa="DC PSP PSU" xmlns="


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      1192.168.2.44975713.107.246.604436872C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
      TimestampBytes transferredDirectionData
      2024-10-01 19:53:09 UTC207OUTGET /rules/rule490016v3s19.xml HTTP/1.1
      Connection: Keep-Alive
      Accept-Encoding: gzip
      User-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Excel 16.0.16827; Pro)
      Host: otelrules.azureedge.net
      2024-10-01 19:53:09 UTC491INHTTP/1.1 200 OK
      Date: Tue, 01 Oct 2024 19:53:09 GMT
      Content-Type: text/xml
      Content-Length: 777
      Connection: close
      Cache-Control: public, max-age=604800, immutable
      Last-Modified: Tue, 09 Apr 2024 00:28:04 GMT
      ETag: "0x8DC582BEC2AAB32"
      x-ms-request-id: 55f4d361-401e-0015-12c5-130e8d000000
      x-ms-version: 2018-03-28
      x-azure-ref: 20241001T195309Z-15767c5fc552g4w83buhsr3htc00000008gg00000000cmbu
      x-fd-int-roxy-purgeid: 0
      X-Cache: TCP_HIT
      X-Cache-Info: L1_T2
      Accept-Ranges: bytes
      2024-10-01 19:53:09 UTC777INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 34 39 30 30 31 36 22 20 56 3d 22 33 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 46 65 65 64 62 61 63 6b 2e 53 75 72 76 65 79 2e 46 6c 6f 6f 64 67 61 74 65 43 6c 69 65 6e 74 2e 52 6f 61 6d 69 6e 67 53 75 63 63 65 73 73 66 75 6c 52 65 61 64 57 72 69 74 65 22 20 41 54 54 3d 22 64 37 39 65 38 32 34 33 38 36 63 34 34 34 31 63 62 38 63 31 64 34 61 65 31 35 36 39 30 35 32 36 2d 62 64 34 34 33 33 30 39 2d 35 34 39 34 2d 34 34 34 61 2d 61 62 61 39 2d 30 61 66 39 65 65 66 39 39 66 38 34 2d 37 33 36 30 22 20 54 3d 22 55 70 6c 6f 61 64 2d 4d 65 64 69 75 6d 22 20 44 4c 3d 22 4e 22 20 44 43 61 3d 22 50
      Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="490016" V="3" DC="SM" EN="Office.Feedback.Survey.FloodgateClient.RoamingSuccessfulReadWrite" ATT="d79e824386c4441cb8c1d4ae15690526-bd443309-5494-444a-aba9-0af9eef99f84-7360" T="Upload-Medium" DL="N" DCa="P


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      2192.168.2.44975413.107.246.604436872C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
      TimestampBytes transferredDirectionData
      2024-10-01 19:53:09 UTC208OUTGET /rules/rule170012v12s19.xml HTTP/1.1
      Connection: Keep-Alive
      Accept-Encoding: gzip
      User-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Excel 16.0.16827; Pro)
      Host: otelrules.azureedge.net
      2024-10-01 19:53:09 UTC584INHTTP/1.1 200 OK
      Date: Tue, 01 Oct 2024 19:53:09 GMT
      Content-Type: text/xml
      Content-Length: 1353
      Connection: close
      Vary: Accept-Encoding
      Vary: Accept-Encoding
      Vary: Accept-Encoding
      Vary: Accept-Encoding
      Cache-Control: public, max-age=604800, immutable
      Last-Modified: Sat, 25 May 2024 18:28:18 GMT
      ETag: "0x8DC7CE8734A2850"
      x-ms-request-id: 0c52b10d-f01e-0096-56c5-1310ef000000
      x-ms-version: 2018-03-28
      x-azure-ref: 20241001T195309Z-15767c5fc55xgp8c992y5v5w1800000008fg000000012t8b
      x-fd-int-roxy-purgeid: 0
      X-Cache: TCP_HIT
      X-Cache-Info: L1_T2
      Accept-Ranges: bytes
      2024-10-01 19:53:09 UTC1353INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 37 30 30 31 32 22 20 56 3d 22 31 32 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 47 72 61 70 68 69 63 73 2e 47 56 69 7a 49 6e 6b 53 74 72 6f 6b 65 22 20 41 54 54 3d 22 63 66 63 66 64 62 39 31 63 36 38 63 34 33 32 39 62 62 38 62 37 63 62 37 62 61 62 62 33 63 66 37 2d 65 30 38 32 63 32 66 32 2d 65 66 31 64 2d 34 32 37 61 2d 61 63 34 64 2d 62 30 62 37 30 30 61 66 65 37 61 37 2d 37 36 35 35 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 43 61 3d 22 50 53 55 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 54 53 20 54
      Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="170012" V="12" DC="SM" EN="Office.Graphics.GVizInkStroke" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" SP="CriticalBusinessImpact" DCa="PSU" xmlns=""> <S> <UTS T


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      3192.168.2.44975513.107.246.604436872C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
      TimestampBytes transferredDirectionData
      2024-10-01 19:53:09 UTC206OUTGET /rules/rule63067v4s19.xml HTTP/1.1
      Connection: Keep-Alive
      Accept-Encoding: gzip
      User-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Excel 16.0.16827; Pro)
      Host: otelrules.azureedge.net
      2024-10-01 19:53:09 UTC584INHTTP/1.1 200 OK
      Date: Tue, 01 Oct 2024 19:53:09 GMT
      Content-Type: text/xml
      Content-Length: 2871
      Connection: close
      Vary: Accept-Encoding
      Vary: Accept-Encoding
      Vary: Accept-Encoding
      Vary: Accept-Encoding
      Cache-Control: public, max-age=604800, immutable
      Last-Modified: Tue, 09 Apr 2024 00:28:05 GMT
      ETag: "0x8DC582BEC5E84E0"
      x-ms-request-id: 6fb6f6f2-401e-0083-5cc5-13075c000000
      x-ms-version: 2018-03-28
      x-azure-ref: 20241001T195309Z-15767c5fc554w2fgapsyvy8ua0000000081000000000a3uk
      x-fd-int-roxy-purgeid: 0
      X-Cache: TCP_HIT
      X-Cache-Info: L1_T2
      Accept-Ranges: bytes
      2024-10-01 19:53:09 UTC2871INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 36 33 30 36 37 22 20 56 3d 22 34 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 49 64 65 6e 74 69 74 79 2e 53 73 70 69 50 72 6f 6d 70 74 57 69 6e 33 32 22 20 41 54 54 3d 22 35 63 36 35 62 62 63 34 65 64 62 66 34 38 30 64 39 36 33 37 61 63 65 30 34 64 36 32 62 64 39 38 2d 31 32 38 34 34 38 39 33 2d 38 61 62 39 2d 34 64 64 65 2d 62 38 35 30 2d 35 36 31 32 63 62 31 32 65 30 66 32 2d 37 38 32 32 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 44 43 61 3d 22 44 43 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20
      Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="63067" V="4" DC="SM" EN="Office.Identity.SspiPromptWin32" ATT="5c65bbc4edbf480d9637ace04d62bd98-12844893-8ab9-4dde-b850-5612cb12e0f2-7822" SP="CriticalBusinessImpact" DL="A" DCa="DC" xmlns=""> <S>


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      4192.168.2.44975313.107.246.604436872C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
      TimestampBytes transferredDirectionData
      2024-10-01 19:53:09 UTC207OUTGET /rules/rule170022v2s19.xml HTTP/1.1
      Connection: Keep-Alive
      Accept-Encoding: gzip
      User-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Excel 16.0.16827; Pro)
      Host: otelrules.azureedge.net
      2024-10-01 19:53:09 UTC491INHTTP/1.1 200 OK
      Date: Tue, 01 Oct 2024 19:53:09 GMT
      Content-Type: text/xml
      Content-Length: 756
      Connection: close
      Cache-Control: public, max-age=604800, immutable
      Last-Modified: Sat, 27 Jul 2024 15:36:11 GMT
      ETag: "0x8DCAE51D7B4AB9D"
      x-ms-request-id: 240404f3-c01e-000b-68c5-13e255000000
      x-ms-version: 2018-03-28
      x-azure-ref: 20241001T195309Z-15767c5fc55d6fcl6x6bw8cpdc00000008c000000000h4tv
      x-fd-int-roxy-purgeid: 0
      X-Cache: TCP_HIT
      X-Cache-Info: L1_T2
      Accept-Ranges: bytes
      2024-10-01 19:53:09 UTC756INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 37 30 30 32 32 22 20 56 3d 22 32 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 47 72 61 70 68 69 63 73 2e 47 56 69 73 49 6e 6b 4c 6f 61 64 22 20 41 54 54 3d 22 63 66 63 66 64 62 39 31 63 36 38 63 34 33 32 39 62 62 38 62 37 63 62 37 62 61 62 62 33 63 66 37 2d 65 30 38 32 63 32 66 32 2d 65 66 31 64 2d 34 32 37 61 2d 61 63 34 64 2d 62 30 62 37 30 30 61 66 65 37 61 37 2d 37 36 35 35 22 20 53 3d 22 31 22 20 44 43 61 3d 22 50 53 55 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 54 53 20 54 3d 22 31 22 20 49 64 3d 22 62 38 69 70 6a 22 20 41 3d 22 61 6e 75 69 35 22
      Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="170022" V="2" DC="SM" EN="Office.Graphics.GVisInkLoad" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" S="1" DCa="PSU" xmlns=""> <S> <UTS T="1" Id="b8ipj" A="anui5"


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      5192.168.2.44975913.107.246.604436872C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
      TimestampBytes transferredDirectionData
      2024-10-01 19:53:10 UTC207OUTGET /rules/rule324002v5s19.xml HTTP/1.1
      Connection: Keep-Alive
      Accept-Encoding: gzip
      User-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Excel 16.0.16827; Pro)
      Host: otelrules.azureedge.net
      2024-10-01 19:53:10 UTC491INHTTP/1.1 200 OK
      Date: Tue, 01 Oct 2024 19:53:10 GMT
      Content-Type: text/xml
      Content-Length: 833
      Connection: close
      Cache-Control: public, max-age=604800, immutable
      Last-Modified: Tue, 09 Apr 2024 00:27:33 GMT
      ETag: "0x8DC582BD9758B35"
      x-ms-request-id: 36d17ada-601e-0002-50c5-13a786000000
      x-ms-version: 2018-03-28
      x-azure-ref: 20241001T195310Z-15767c5fc554l9xf959gp9cb1s00000002p000000000ezh7
      x-fd-int-roxy-purgeid: 0
      X-Cache: TCP_HIT
      X-Cache-Info: L1_T2
      Accept-Ranges: bytes
      2024-10-01 19:53:10 UTC833INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 33 32 34 30 30 32 22 20 56 3d 22 35 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 45 78 74 65 6e 73 69 62 69 6c 69 74 79 2e 56 62 61 54 65 6c 65 6d 65 74 72 79 44 65 63 6c 61 72 65 22 20 41 54 54 3d 22 64 62 33 33 34 62 33 30 31 65 37 62 34 37 34 64 62 35 65 30 66 30 32 66 30 37 63 35 31 61 34 37 2d 61 31 62 35 62 63 33 36 2d 31 62 62 65 2d 34 38 32 66 2d 61 36 34 61 2d 63 32 64 39 63 62 36 30 36 37 30 36 2d 37 34 33 39 22 20 44 43 61 3d 22 44 43 20 50 53 50 20 50 53 55 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 54 53 20 54 3d 22 31 22 20 49 64 3d 22 62 30
      Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="324002" V="5" DC="SM" EN="Office.Extensibility.VbaTelemetryDeclare" ATT="db334b301e7b474db5e0f02f07c51a47-a1b5bc36-1bbe-482f-a64a-c2d9cb606706-7439" DCa="DC PSP PSU" xmlns=""> <S> <UTS T="1" Id="b0


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      6192.168.2.44975813.107.246.604436872C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
      TimestampBytes transferredDirectionData
      2024-10-01 19:53:10 UTC207OUTGET /rules/rule324003v5s19.xml HTTP/1.1
      Connection: Keep-Alive
      Accept-Encoding: gzip
      User-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Excel 16.0.16827; Pro)
      Host: otelrules.azureedge.net
      2024-10-01 19:53:10 UTC491INHTTP/1.1 200 OK
      Date: Tue, 01 Oct 2024 19:53:10 GMT
      Content-Type: text/xml
      Content-Length: 716
      Connection: close
      Cache-Control: public, max-age=604800, immutable
      Last-Modified: Tue, 09 Apr 2024 00:27:34 GMT
      ETag: "0x8DC582BD9F5CC0A"
      x-ms-request-id: a3754404-d01e-005a-08c5-137fd9000000
      x-ms-version: 2018-03-28
      x-azure-ref: 20241001T195310Z-15767c5fc55tsfp92w7yna557w00000008eg00000000pnzm
      x-fd-int-roxy-purgeid: 0
      X-Cache: TCP_HIT
      X-Cache-Info: L1_T2
      Accept-Ranges: bytes
      2024-10-01 19:53:10 UTC716INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 33 32 34 30 30 33 22 20 56 3d 22 35 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 45 78 74 65 6e 73 69 62 69 6c 69 74 79 2e 56 62 61 54 65 6c 65 6d 65 74 72 79 52 65 66 65 72 65 6e 63 65 64 4c 69 62 72 61 72 79 22 20 41 54 54 3d 22 64 62 33 33 34 62 33 30 31 65 37 62 34 37 34 64 62 35 65 30 66 30 32 66 30 37 63 35 31 61 34 37 2d 61 31 62 35 62 63 33 36 2d 31 62 62 65 2d 34 38 32 66 2d 61 36 34 61 2d 63 32 64 39 63 62 36 30 36 37 30 36 2d 37 34 33 39 22 20 44 43 61 3d 22 44 43 20 50 53 50 20 50 53 55 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 54 53 20 54 3d
      Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="324003" V="5" DC="SM" EN="Office.Extensibility.VbaTelemetryReferencedLibrary" ATT="db334b301e7b474db5e0f02f07c51a47-a1b5bc36-1bbe-482f-a64a-c2d9cb606706-7439" DCa="DC PSP PSU" xmlns=""> <S> <UTS T=


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      7192.168.2.44976013.107.246.604436872C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
      TimestampBytes transferredDirectionData
      2024-10-01 19:53:10 UTC207OUTGET /rules/rule324004v4s19.xml HTTP/1.1
      Connection: Keep-Alive
      Accept-Encoding: gzip
      User-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Excel 16.0.16827; Pro)
      Host: otelrules.azureedge.net
      2024-10-01 19:53:10 UTC491INHTTP/1.1 200 OK
      Date: Tue, 01 Oct 2024 19:53:10 GMT
      Content-Type: text/xml
      Content-Length: 738
      Connection: close
      Cache-Control: public, max-age=604800, immutable
      Last-Modified: Tue, 09 Apr 2024 00:27:34 GMT
      ETag: "0x8DC582BD9FE7D4B"
      x-ms-request-id: 79ea2b94-301e-0052-50c5-1365d6000000
      x-ms-version: 2018-03-28
      x-azure-ref: 20241001T195310Z-15767c5fc55kg97hfq5uqyxxaw00000008mg000000000a5e
      x-fd-int-roxy-purgeid: 0
      X-Cache: TCP_HIT
      X-Cache-Info: L1_T2
      Accept-Ranges: bytes
      2024-10-01 19:53:10 UTC738INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 33 32 34 30 30 34 22 20 56 3d 22 34 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 45 78 74 65 6e 73 69 62 69 6c 69 74 79 2e 56 62 61 54 65 6c 65 6d 65 74 72 79 43 6f 6d 4f 62 6a 65 63 74 49 6e 73 74 61 6e 74 69 61 74 65 64 22 20 41 54 54 3d 22 64 62 33 33 34 62 33 30 31 65 37 62 34 37 34 64 62 35 65 30 66 30 32 66 30 37 63 35 31 61 34 37 2d 61 31 62 35 62 63 33 36 2d 31 62 62 65 2d 34 38 32 66 2d 61 36 34 61 2d 63 32 64 39 63 62 36 30 36 37 30 36 2d 37 34 33 39 22 20 44 43 61 3d 22 44 43 20 50 53 50 20 50 53 55 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 54
      Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="324004" V="4" DC="SM" EN="Office.Extensibility.VbaTelemetryComObjectInstantiated" ATT="db334b301e7b474db5e0f02f07c51a47-a1b5bc36-1bbe-482f-a64a-c2d9cb606706-7439" DCa="DC PSP PSU" xmlns=""> <S> <UT


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      8192.168.2.44976113.107.246.604436872C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
      TimestampBytes transferredDirectionData
      2024-10-01 19:53:10 UTC207OUTGET /rules/rule324005v2s19.xml HTTP/1.1
      Connection: Keep-Alive
      Accept-Encoding: gzip
      User-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Excel 16.0.16827; Pro)
      Host: otelrules.azureedge.net
      2024-10-01 19:53:10 UTC491INHTTP/1.1 200 OK
      Date: Tue, 01 Oct 2024 19:53:10 GMT
      Content-Type: text/xml
      Content-Length: 599
      Connection: close
      Cache-Control: public, max-age=604800, immutable
      Last-Modified: Tue, 09 Apr 2024 00:26:51 GMT
      ETag: "0x8DC582BC0B3C3C8"
      x-ms-request-id: f4b5ee0a-a01e-0053-7026-148603000000
      x-ms-version: 2018-03-28
      x-azure-ref: 20241001T195310Z-15767c5fc55rv8zjq9dg0musxg00000008kg000000004evc
      x-fd-int-roxy-purgeid: 0
      X-Cache: TCP_HIT
      X-Cache-Info: L1_T2
      Accept-Ranges: bytes
      2024-10-01 19:53:10 UTC599INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 33 32 34 30 30 35 22 20 56 3d 22 32 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 45 78 74 65 6e 73 69 62 69 6c 69 74 79 2e 56 62 61 54 65 6c 65 6d 65 74 72 79 43 6f 6d 70 69 6c 65 22 20 41 54 54 3d 22 64 62 33 33 34 62 33 30 31 65 37 62 34 37 34 64 62 35 65 30 66 30 32 66 30 37 63 35 31 61 34 37 2d 61 31 62 35 62 63 33 36 2d 31 62 62 65 2d 34 38 32 66 2d 61 36 34 61 2d 63 32 64 39 63 62 36 30 36 37 30 36 2d 37 34 33 39 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 43 61 3d 22 44 43 20 50 53 50 20 50 53 55 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a
      Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="324005" V="2" DC="SM" EN="Office.Extensibility.VbaTelemetryCompile" ATT="db334b301e7b474db5e0f02f07c51a47-a1b5bc36-1bbe-482f-a64a-c2d9cb606706-7439" SP="CriticalBusinessImpact" DCa="DC PSP PSU" xmlns="">


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      9192.168.2.44976213.107.246.604436872C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
      TimestampBytes transferredDirectionData
      2024-10-01 19:53:10 UTC207OUTGET /rules/rule324006v2s19.xml HTTP/1.1
      Connection: Keep-Alive
      Accept-Encoding: gzip
      User-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Excel 16.0.16827; Pro)
      Host: otelrules.azureedge.net
      2024-10-01 19:53:10 UTC491INHTTP/1.1 200 OK
      Date: Tue, 01 Oct 2024 19:53:10 GMT
      Content-Type: text/xml
      Content-Length: 599
      Connection: close
      Cache-Control: public, max-age=604800, immutable
      Last-Modified: Tue, 09 Apr 2024 00:26:44 GMT
      ETag: "0x8DC582BBC83D642"
      x-ms-request-id: 0c52b2bd-f01e-0096-74c5-1310ef000000
      x-ms-version: 2018-03-28
      x-azure-ref: 20241001T195310Z-15767c5fc5546rn6ch9zv310e000000001ag00000000zycv
      x-fd-int-roxy-purgeid: 0
      X-Cache: TCP_HIT
      X-Cache-Info: L1_T2
      Accept-Ranges: bytes
      2024-10-01 19:53:10 UTC599INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 33 32 34 30 30 36 22 20 56 3d 22 32 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 45 78 74 65 6e 73 69 62 69 6c 69 74 79 2e 56 62 61 54 65 6c 65 6d 65 74 72 79 53 68 6f 77 49 64 65 22 20 41 54 54 3d 22 64 62 33 33 34 62 33 30 31 65 37 62 34 37 34 64 62 35 65 30 66 30 32 66 30 37 63 35 31 61 34 37 2d 61 31 62 35 62 63 33 36 2d 31 62 62 65 2d 34 38 32 66 2d 61 36 34 61 2d 63 32 64 39 63 62 36 30 36 37 30 36 2d 37 34 33 39 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 43 61 3d 22 44 43 20 50 53 50 20 50 53 55 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a
      Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="324006" V="2" DC="SM" EN="Office.Extensibility.VbaTelemetryShowIde" ATT="db334b301e7b474db5e0f02f07c51a47-a1b5bc36-1bbe-482f-a64a-c2d9cb606706-7439" SP="CriticalBusinessImpact" DCa="DC PSP PSU" xmlns="">


      Click to jump to process

      Click to jump to process

      Click to dive into process behavior distribution

      Click to jump to process

      Target ID:0
      Start time:15:51:56
      Start date:01/10/2024
      Path:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
      Wow64 process (32bit):true
      Commandline:"C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" /automation -Embedding
      Imagebase:0x1d0000
      File size:53'161'064 bytes
      MD5 hash:4A871771235598812032C822E6F68F19
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:high
      Has exited:false

      Target ID:5
      Start time:15:53:03
      Start date:01/10/2024
      Path:C:\Windows\splwow64.exe
      Wow64 process (32bit):false
      Commandline:C:\Windows\splwow64.exe 12288
      Imagebase:0x7ff70f330000
      File size:163'840 bytes
      MD5 hash:77DE7761B037061C7C112FD3C5B91E73
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:high
      Has exited:false

      No disassembly