Windows
Analysis Report
PO20241008.xls
Overview
General Information
Detection
Score: | 64 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- EXCEL.EXE (PID: 2436 cmdline:
"C:\Progra m Files (x 86)\Micros oft Office \Root\Offi ce16\EXCEL .EXE" /aut omation -E mbedding MD5: 4A871771235598812032C822E6F68F19) - splwow64.exe (PID: 6844 cmdline:
C:\Windows \splwow64. exe 12288 MD5: 77DE7761B037061C7C112FD3C5B91E73)
- EXCEL.EXE (PID: 2632 cmdline:
"C:\Progra m Files (x 86)\Micros oft Office \Root\Offi ce16\EXCEL .EXE" "C:\ Users\user \Desktop\P O20241008. xls" MD5: 4A871771235598812032C822E6F68F19)
- cleanup
System Summary |
---|
Source: | Author: Christopher Peacock '@securepeacock', SCYTHE '@scythe_io', Florian Roth '@Neo23x0", Tim Shelton: |
Source: | Author: X__Junior (Nextron Systems): |
Click to jump to signature section
AV Detection |
---|
Source: | ReversingLabs: |
Source: | Joe Sandbox ML: |
Source: | File opened: | Jump to behavior |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | DNS query: | ||
Source: | DNS query: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | Memory has grown: |
Source: | IP Address: | ||
Source: | IP Address: | ||
Source: | IP Address: |
Source: | JA3 fingerprint: | ||
Source: | JA3 fingerprint: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
System Summary |
---|
Source: | OCR: | ||
Source: | OCR: | ||
Source: | OCR: | ||
Source: | OCR: | ||
Source: | OCR: | ||
Source: | OCR: |
Source: | OLE: | ||
Source: | OLE: | ||
Source: | OLE: | ||
Source: | OLE: |
Source: | OLE indicator, VBA macros: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | OLE indicator, Workbook stream: | ||
Source: | OLE indicator, Workbook stream: |
Source: | File read: | Jump to behavior |
Source: | ReversingLabs: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Source: | Key opened: | Jump to behavior |
Source: | Static file information: |
Source: | File opened: | Jump to behavior |
Source: | Initial sample: |
Source: | Initial sample: |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Source: | Stream path 'MBD0015E099/MBD002A6130/CONTENTS' entropy: | ||
Source: | Stream path 'Workbook' entropy: | ||
Source: | Stream path 'MBD0015E099/MBD002A6130/CONTENTS' entropy: | ||
Source: | Stream path 'Workbook' entropy: |
Source: | Window / User API: | Jump to behavior |
Source: | Last function: | ||
Source: | Last function: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Process information queried: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 1 Scripting | Valid Accounts | 3 Exploitation for Client Execution | 1 Scripting | 1 Process Injection | 2 Masquerading | OS Credential Dumping | 1 Process Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 Extra Window Memory Injection | 1 Disable or Modify Tools | LSASS Memory | 1 Virtualization/Sandbox Evasion | Remote Desktop Protocol | Data from Removable Media | 1 Ingress Tool Transfer | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 1 Virtualization/Sandbox Evasion | Security Account Manager | 1 Application Window Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | 2 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 Process Injection | NTDS | 1 File and Directory Discovery | Distributed Component Object Model | Input Capture | 13 Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 Obfuscated Files or Information | LSA Secrets | 1 System Information Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 1 Extra Window Memory Injection | Cached Domain Credentials | Wi-Fi Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
13% | ReversingLabs | Document-PDF.Trojan.Heuristic | ||
100% | Joe Sandbox ML |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
wrath.me | 188.114.96.3 | true | false | unknown | |
s-part-0017.t-0009.t-msedge.net | 13.107.246.45 | true | false | unknown | |
s-part-0032.t-0009.t-msedge.net | 13.107.246.60 | true | false | unknown | |
18.31.95.13.in-addr.arpa | unknown | unknown | false | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
188.114.96.3 | wrath.me | European Union | 13335 | CLOUDFLARENETUS | false | |
13.107.246.60 | s-part-0032.t-0009.t-msedge.net | United States | 8068 | MICROSOFT-CORP-MSN-AS-BLOCKUS | false | |
72.5.42.5 | unknown | United States | 16769 | UNASSIGNED | false |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1529028 |
Start date and time: | 2024-10-08 15:36:18 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 13s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowsofficecookbook.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Run name: | Potential for more IOCs and behavior |
Number of analysed new started processes analysed: | 11 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | PO20241008.xls |
Detection: | MAL |
Classification: | mal64.winXLS@4/20@2/3 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, sppsvc.exe, WMIADAP.exe, SIHClient.exe, WmiPrvSE.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 52.109.76.240, 52.113.194.132, 184.28.90.27, 52.109.76.243, 20.189.173.16, 52.109.89.18, 20.42.73.28
- Excluded domains from analysis (whitelisted): slscr.update.microsoft.com, otelrules.afd.azureedge.net, weu-azsc-config.officeapps.live.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, eur.roaming1.live.com.akadns.net, neu-azsc-000.roaming.officeapps.live.com, mobile.events.data.microsoft.com, ecs-office.s-0005.s-msedge.net, roaming.officeapps.live.com, ocsp.digicert.com, login.live.com, e16604.g.akamaiedge.net, officeclient.microsoft.com, prod.fs.microsoft.com.akadns.net, ecs.office.com, self-events-data.trafficmanager.net, client.wns.windows.com, fs.microsoft.com, otelrules.azureedge.net, prod.configsvc1.live.com.akadns.net, self.events.data.microsoft.com, ctldl.windowsupdate.com, prod.roaming1.live.com.akadns.net, s-0005-office.config.skype.com, onedscolprdwus17.westus.cloudapp.azure.com, fe3cr.delivery.mp.microsoft.com, neu-azsc-config.officeapps.live.com, s-0005.s-msedge.net, config.officeapps.live.com, osiprod-neu-buff-azsc-000.northeurope.cloudapp
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtQueryAttributesFile calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- Report size getting too big, too many NtReadVirtualMemory calls found.
- Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
- VT rate limit hit for: PO20241008.xls
Time | Type | Description |
---|---|---|
09:38:46 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
188.114.96.3 | Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| |
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | Pony | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
13.107.246.60 | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
wrath.me | Get hash | malicious | Remcos | Browse |
| |
s-part-0017.t-0009.t-msedge.net | Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| |
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | Credential Flusher | Browse |
| ||
Get hash | malicious | Xmrig | Browse |
| ||
Get hash | malicious | XWorm | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
s-part-0032.t-0009.t-msedge.net | Get hash | malicious | LummaC, Vidar | Browse |
| |
Get hash | malicious | RedLine | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Stealc | Browse |
| ||
Get hash | malicious | LummaC, Vidar | Browse |
| ||
Get hash | malicious | Stealc | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
UNASSIGNED | Get hash | malicious | AgentTesla | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
CLOUDFLARENETUS | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | NetSupport RAT | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | AgentTesla, PureLog Stealer | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
MICROSOFT-CORP-MSN-AS-BLOCKUS | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Phisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
6271f898ce5be7dd52b0fc260d0662b3 | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Outlook Phishing, HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HtmlDropper | Browse |
| ||
Get hash | malicious | Credential Flusher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
a0e9f5d64349fb13191bc781f81f42e1 | Get hash | malicious | LummaC, Vidar | Browse |
| |
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | LummaC | Browse |
|
C:\Program Files (x86)\Microsoft Office\root\vfs\Common AppData\Microsoft\OFFICE\Heartbeat\HeartbeatCache.xml
Download File
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 118 |
Entropy (8bit): | 3.5700810731231707 |
Encrypted: | false |
SSDEEP: | 3:QaklTlAlXMLLmHlIlFLlmIK/5lTn84vlJlhlXlDHlA6l3l6Als:QFulcLk04/5p8GVz6QRq |
MD5: | 573220372DA4ED487441611079B623CD |
SHA1: | 8F9D967AC6EF34640F1F0845214FBC6994C0CB80 |
SHA-256: | BE84B842025E4241BFE0C9F7B8F86A322E4396D893EF87EA1E29C74F47B6A22D |
SHA-512: | F19FA3583668C3AF92A9CEF7010BD6ECEC7285F9C8665F2E9528DBA606F105D9AF9B1DB0CF6E7F77EF2E395943DC0D5CB37149E773319078688979E4024F9DD7 |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 934 |
Entropy (8bit): | 2.7129194926077287 |
Encrypted: | false |
SSDEEP: | 24:YIrNvpCHhFGMfzLRwcftR/8AJp9WtAZRJ5poIHWPZqy:YmbCHaMfzLmcL8AJtfJ52IH2Zh |
MD5: | AEA8676011F651E962233964C56EC078 |
SHA1: | 48A16B5ED64B901BD474918730E8428101BCB382 |
SHA-256: | F66BFE3FB3CF9C5973527B3C6ED0927D4056DADF962D0B64B87FD97F852191F9 |
SHA-512: | 76ED966584166233A500D2400C012929DC76D1DFF397C3A3D014FB7ECE767730966655974A3B1BE5B6E0C03CC21B3A38B3029916628DCC07D07CC1A8F7031748 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 98872 |
Entropy (8bit): | 2.681314822793575 |
Encrypted: | false |
SSDEEP: | 768:XOtIvF1D/7ohBb66dZKKBTon4qQbApQKyE:+f5E |
MD5: | F37CEAB7E8E934F2580138A386C9D067 |
SHA1: | 9A33CDE7D9EB3D0B2D71C3A400464A2ABB1568DD |
SHA-256: | CE4084B51EE8A3152C97FFF64E03956F98BAC50B033932E18F84442AA9B020C7 |
SHA-512: | A77AFCC359F887E806779BE5B3D13307DA02B4FED7CC2CC59394CC2803EAFBF659E4485CC970B0C54073C0C5D974E70ACF277C8AF3AE534551EE74BA52A19DEB |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 97168 |
Entropy (8bit): | 2.644024661766287 |
Encrypted: | false |
SSDEEP: | 768:aBRH2Rsq1DE7ohxp6A0+KSBToxEkFapQKJ3p:cJ+f |
MD5: | FCA48261B12CA04BADC738EB52D2191A |
SHA1: | AB471CEE4F1346A357F18FAF2F2F75FDC0567621 |
SHA-256: | 619F59C860464C43F1485BE264AABB98FACEC1BCE96848FBF8DE542191FC62A9 |
SHA-512: | E9B20225B0C750A5A669201040D9E02451FE80275E2E9980A3BB4A197295903BC9B9295053E5220A2B70E5D463BF018CB41F3CB46118C5E62481E52BED40A7F3 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 76472 |
Entropy (8bit): | 3.025081600163608 |
Encrypted: | false |
SSDEEP: | 384:luYYST5PIYfLe2b52XPl6hAJC00EddMdf0Ii90Z5xxr8sdEdeC:4igYfqg52XPl6hAJC0irRHC |
MD5: | A4B79FF3D7725F69AB98C49A72805D64 |
SHA1: | 8617AF425CE74F816B2CE28FF7BF08A7F5317030 |
SHA-256: | 2DE8B86E62DE48780D92E82B3132F559DF0324A000F9BAFC8CAF3D2789D17CE5 |
SHA-512: | 3B7E25DBDFDAD51FFD8DB140091405FABD3242704C0FD0517CEB10C59E5AF57098CA41C3DCA9F9E80045D8A75EE8415927467457E636EA475C0BE95063C94C49 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 8084 |
Entropy (8bit): | 2.570503528684488 |
Encrypted: | false |
SSDEEP: | 96:j+RiOO++Z397Q2Acgze0xBdEQzBfCC7Boff8oBJ6ANQ4HJV:jt7ecgKgvzBArH |
MD5: | A0D51FBAA34316A0B3E02FA2B5BEA0B8 |
SHA1: | 01B3F570EFCA831762B154AC65E11C122319D35D |
SHA-256: | BC55995ADDDFBE0105BDACE8E1603EA7E9DA698C0BDC7E91F043578BF6B28157 |
SHA-512: | 93E08DF7E102CCD3D9077284E1E80369A21BA86B9194B72528BB140ABA83E65E7E2DC59471E2484AE805AF1C13E41C6A5273150E2EFAB06CABFA21BC889405E5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 97168 |
Entropy (8bit): | 2.644024661766287 |
Encrypted: | false |
SSDEEP: | 768:aBRH2Rsq1DE7ohxp6A0+KSBToxEkFapQKJ3p:cJ+f |
MD5: | FCA48261B12CA04BADC738EB52D2191A |
SHA1: | AB471CEE4F1346A357F18FAF2F2F75FDC0567621 |
SHA-256: | 619F59C860464C43F1485BE264AABB98FACEC1BCE96848FBF8DE542191FC62A9 |
SHA-512: | E9B20225B0C750A5A669201040D9E02451FE80275E2E9980A3BB4A197295903BC9B9295053E5220A2B70E5D463BF018CB41F3CB46118C5E62481E52BED40A7F3 |
Malicious: | false |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 97168 |
Entropy (8bit): | 2.6906748419763025 |
Encrypted: | false |
SSDEEP: | 768:aBtRR1Jl1DW7ohBb66mQKSBTo9fAiFapQKX3p:c//b |
MD5: | E1527D440968C6AC201210FB28CB918A |
SHA1: | BE377A31AE15A896487A0A89C767F2E0CD72A753 |
SHA-256: | 78721534B2ED4737B1823C8EA152C9DF3DDA1B504F90E34CB32929F64FF94E25 |
SHA-512: | 4D52AA1C47DCA30D8240A20F21399D4C59FA6ACA677D530EB9096E548771FCB9DE046F8BDFCF50E99FE7DCF636421F9AFEABBCCCEB5FF4454DCB8B11C460B8C6 |
Malicious: | false |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 38272 |
Entropy (8bit): | 2.8200425031385645 |
Encrypted: | false |
SSDEEP: | 192:6/UjPGlVrhaHoq7x0ii1lild6rMT54GtXU+j9hMQmlC+a6gz5nCf5OBgJP+SKA:6/1MH61lq4GtXJMQmlC+a6gz5SOyJ1/ |
MD5: | C898CDC91D0BD5EFB41E576B8A19E931 |
SHA1: | B9ED5CAC5A526CF8095AB8F8CE36C39F78422407 |
SHA-256: | 044E7012311B28991E687A081E1AC94B7D7EB80F1BE1970F519E949D01A05CA2 |
SHA-512: | 6BCD700AAB23B2205E8294C3071158CA42D4BA6B4B098CA6B511A386FF2E1F8D6B6A3BED4F307475F03161F96425194DEA5581411D3544E95F6D17BCD3264019 |
Malicious: | false |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 2342852 |
Entropy (8bit): | 2.6417290025884554 |
Encrypted: | false |
SSDEEP: | 6144:D8elSEv4mD3f5ReZdZJElOFmBwPuqOag8J0tuGOE68J0P:DJlSDmzCJEu5Lg00jh600P |
MD5: | B2020C2F370E4625A9EA3C36EEA00DAF |
SHA1: | 3BCAF1F0CC2E64FDEC9FD0941BA7903A4772F093 |
SHA-256: | BF45DCFBDBC932E7AE776DA6BDCB2026E3C51924BFC017DB37482C68C8722C32 |
SHA-512: | 78F17558C35106A343B868C35C9429380CA6F606ABCD7644CF866B67CCB157A57F050173B39C1D4B6C86A20039E4AC7F0B12CA564D754C9DC163C877583C7C08 |
Malicious: | false |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 97168 |
Entropy (8bit): | 2.644024661766287 |
Encrypted: | false |
SSDEEP: | 768:aBRH2Rsq1DE7ohxp6A0+KSBToxEkFapQKJ3p:cJ+f |
MD5: | FCA48261B12CA04BADC738EB52D2191A |
SHA1: | AB471CEE4F1346A357F18FAF2F2F75FDC0567621 |
SHA-256: | 619F59C860464C43F1485BE264AABB98FACEC1BCE96848FBF8DE542191FC62A9 |
SHA-512: | E9B20225B0C750A5A669201040D9E02451FE80275E2E9980A3BB4A197295903BC9B9295053E5220A2B70E5D463BF018CB41F3CB46118C5E62481E52BED40A7F3 |
Malicious: | false |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 884312 |
Entropy (8bit): | 1.2944965349348616 |
Encrypted: | false |
SSDEEP: | 1536:W3dki8JungPuzcn6F1Tny9Cie/koPs9h9RHJFUrnT15vWP5cPpmJ2dvRaQq3vMog:Hux/ZiOE85e+8J2dvRcvMyw |
MD5: | 9ABE7EB352E0DB96B52C99AC2FDEA85F |
SHA1: | 8DC45D02308275BA32B7FFB320A3042256D40C8B |
SHA-256: | EC022DFF1CC8251BA9D849C16431914635473FC5457AE73AA277651B47948869 |
SHA-512: | E43325B927F5365F16118B67E1830B2A0E8CC051D9AEAB144DA6A75751CA39CC1831158270A50ED31BCCBA29C98A56769E516F36C45CB5FAA1BB6ED92CC0A5EB |
Malicious: | false |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 99352 |
Entropy (8bit): | 2.679591044823692 |
Encrypted: | false |
SSDEEP: | 768:hOeIvE1D97ohP46ScVK4BTonxqQbApQKyE:UrQE |
MD5: | A1D8A525C9CF4158D96D1047CAD19968 |
SHA1: | F359A837C8AB9AF86B7E4A180D5694B7F1B851D3 |
SHA-256: | 4F95DCCD6619B83D703850DE8B7B9B69EB595FC248361B5B548C3F42BB9CBE08 |
SHA-512: | 3FB321A34661E187E2A20AD616280263484BBC39CEBD8734BC53BC47DD3C062FF3B2E3DE7DA8CE077555E1DEBEFB7C5A4E8E01E42272CC7C9D22F4DED0A5BE5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 934 |
Entropy (8bit): | 2.7129194926077287 |
Encrypted: | false |
SSDEEP: | 24:YIrNvpCHhFGMfzLRwcftR/8AJp9WtAZRJ5poIHWPZqy:YmbCHaMfzLmcL8AJtfJ52IH2Zh |
MD5: | AEA8676011F651E962233964C56EC078 |
SHA1: | 48A16B5ED64B901BD474918730E8428101BCB382 |
SHA-256: | F66BFE3FB3CF9C5973527B3C6ED0927D4056DADF962D0B64B87FD97F852191F9 |
SHA-512: | 76ED966584166233A500D2400C012929DC76D1DFF397C3A3D014FB7ECE767730966655974A3B1BE5B6E0C03CC21B3A38B3029916628DCC07D07CC1A8F7031748 |
Malicious: | false |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 512 |
Entropy (8bit): | 0.0 |
Encrypted: | false |
SSDEEP: | 3:: |
MD5: | BF619EAC0CDF3F68D496EA9344137E8B |
SHA1: | 5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5 |
SHA-256: | 076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560 |
SHA-512: | DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE |
Malicious: | false |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 155648 |
Entropy (8bit): | 6.842290020855385 |
Encrypted: | false |
SSDEEP: | 3072:gCk3hbdlylKsgwyzcTbWhZFGkE+cLaxHAUdHzxAKywiZDwKRN7TzfuNLfhnIZAlK:9k3hbdlylKsgwyzcTbWhZFVE+WaxHAIs |
MD5: | 2634B62E287ED964F7510C73DB10A674 |
SHA1: | EB1CBC3FDDE6731A96A166C973523ED807945BF3 |
SHA-256: | 499A404B6CEB899B5A10A92F2386AFBF2A34A596F773CB13C7335CC55F15A098 |
SHA-512: | E9FE50FC2E83823F3EF6C0C81DC9AAE83113DDB237151172400AE322236AE634C39139DD842791C8EAFF1E3DF154A37E76D423A8A7504CF9F556218290C84B89 |
Malicious: | false |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 512 |
Entropy (8bit): | 0.0 |
Encrypted: | false |
SSDEEP: | 3:: |
MD5: | BF619EAC0CDF3F68D496EA9344137E8B |
SHA1: | 5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5 |
SHA-256: | 076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560 |
SHA-512: | DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE |
Malicious: | false |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 681984 |
Entropy (8bit): | 7.028222791044042 |
Encrypted: | false |
SSDEEP: | 12288:tARwWYx9wu4hLD3DERnLRmF8DNVrf1x3d2cu69g:ewfx9w/hLbARM8jn399g |
MD5: | 9B53EB041B3703C184C8CD6EB10CDF28 |
SHA1: | 81A9DF5A5A26C073ABA44190013247D9BD6905B4 |
SHA-256: | 1DB5FD568D58CAD9795E8D91A0BDF150657CDE8CEC9C4147519A4FE41EBB6FDC |
SHA-512: | D30A2DAA58F2AA7C85BB9A03D06875CE61E3604A00C2312BBDCF81EEDDD3D3A47A2E151E1E1D89415C42CF25B968184CAC13106D8B2A6601D6FB525DB6AD5C72 |
Malicious: | false |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE |
File Type: | |
Category: | modified |
Size (bytes): | 26 |
Entropy (8bit): | 3.95006375643621 |
Encrypted: | false |
SSDEEP: | 3:ggPYV:rPYV |
MD5: | 187F488E27DB4AF347237FE461A079AD |
SHA1: | 6693BA299EC1881249D59262276A0D2CB21F8E64 |
SHA-256: | 255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309 |
SHA-512: | 89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E |
Malicious: | false |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 681984 |
Entropy (8bit): | 7.028222791044042 |
Encrypted: | false |
SSDEEP: | 12288:tARwWYx9wu4hLD3DERnLRmF8DNVrf1x3d2cu69g:ewfx9w/hLbARM8jn399g |
MD5: | 9B53EB041B3703C184C8CD6EB10CDF28 |
SHA1: | 81A9DF5A5A26C073ABA44190013247D9BD6905B4 |
SHA-256: | 1DB5FD568D58CAD9795E8D91A0BDF150657CDE8CEC9C4147519A4FE41EBB6FDC |
SHA-512: | D30A2DAA58F2AA7C85BB9A03D06875CE61E3604A00C2312BBDCF81EEDDD3D3A47A2E151E1E1D89415C42CF25B968184CAC13106D8B2A6601D6FB525DB6AD5C72 |
Malicious: | true |
Preview: |
File type: | |
Entropy (8bit): | 7.2638458188396084 |
TrID: |
|
File name: | PO20241008.xls |
File size: | 1'094'656 bytes |
MD5: | 2f967a802f4b792f40315232d8232cd7 |
SHA1: | 6d61ccac86a924e895114e0e9b06ee2185075497 |
SHA256: | 5ccf5c84f7c2890c2769eefb521253092d9b5fd73534ebbb8e02acc6858b3684 |
SHA512: | 7f5cad5a50f8a7cb823ca7b2fd9047085340952c10822701d7e1eea86c1cb5b17ee8ce176058741b7c47e18042cfae57a189443b14aaceafd1eaf94c36d4697c |
SSDEEP: | 12288:fmzHJEHAfwu4hCD3DERnLRmF8D3Prf1O3dyFub2Xda7yBinTi0eh6Ro4WcJDS7l8:WLw/hCbARM8/c3j2XE7yxP8oEJDShI |
TLSH: | 8135CF83EA5D4F62CD81423466F71B7A13249C43D622432F22F1772839FBAD06956FAD |
File Content Preview: | ........................>...............................................................................<.......................i.......k...................................................................................................................... |
Icon Hash: | 35ed8e920e8c81b5 |
Document Type: | OLE |
Number of OLE Files: | 1 |
Has Summary Info: | |
Application Name: | Microsoft Excel |
Encrypted Document: | True |
Contains Word Document Stream: | False |
Contains Workbook/Book Stream: | True |
Contains PowerPoint Document Stream: | False |
Contains Visio Document Stream: | False |
Contains ObjectPool Stream: | False |
Flash Objects Count: | 0 |
Contains VBA Macros: | True |
Code Page: | 1252 |
Author: | |
Last Saved By: | |
Create Time: | 2006-09-16 00:00:00 |
Last Saved Time: | 2024-10-08 05:29:01 |
Creating Application: | |
Security: | 1 |
Document Code Page: | 1252 |
Thumbnail Scaling Desired: | False |
Contains Dirty Links: | False |
Shared Document: | False |
Changed Hyperlinks: | False |
Application Version: | 786432 |
General | |
Stream Path: | _VBA_PROJECT_CUR/VBA/Sheet1 |
VBA File Name: | Sheet1.cls |
Stream Size: | 977 |
Data ASCII: | . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . n Y 1 . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 2 . 0 . - |
Data Raw: | 01 16 01 00 00 f0 00 00 00 c4 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff cb 02 00 00 1f 03 00 00 00 00 00 00 01 00 00 00 e7 6e 59 31 00 00 ff ff 23 01 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |
|
General | |
Stream Path: | _VBA_PROJECT_CUR/VBA/Sheet2 |
VBA File Name: | Sheet2.cls |
Stream Size: | 977 |
Data ASCII: | . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . n . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 2 . 0 . - . 0 |
Data Raw: | 01 16 01 00 00 f0 00 00 00 c4 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff cb 02 00 00 1f 03 00 00 00 00 00 00 01 00 00 00 e7 6e eb f4 00 00 ff ff 23 01 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |
|
General | |
Stream Path: | _VBA_PROJECT_CUR/VBA/Sheet3 |
VBA File Name: | Sheet3.cls |
Stream Size: | 977 |
Data ASCII: | . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . n . . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 2 . 0 . - . |
Data Raw: | 01 16 01 00 00 f0 00 00 00 c4 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff cb 02 00 00 1f 03 00 00 00 00 00 00 01 00 00 00 e7 6e ae 0b 00 00 ff ff 23 01 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |
|
General | |
Stream Path: | _VBA_PROJECT_CUR/VBA/ThisWorkbook |
VBA File Name: | ThisWorkbook.cls |
Stream Size: | 985 |
Data ASCII: | . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . n H j . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 1 . 9 . - |
Data Raw: | 01 16 01 00 00 f0 00 00 00 c4 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff cb 02 00 00 1f 03 00 00 00 00 00 00 01 00 00 00 e7 6e 48 6a 00 00 ff ff 23 01 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |
|
General | |
Stream Path: | \x1CompObj |
CLSID: | |
File Type: | data |
Stream Size: | 114 |
Entropy: | 4.25248375192737 |
Base64 Encoded: | True |
Data ASCII: | . . . . . . . . . . . . . . . . . . . F & . . . M i c r o s o f t O f f i c e E x c e l 2 0 0 3 W o r k s h e e t . . . . . B i f f 8 . . . . . E x c e l . S h e e t . 8 . 9 q . . . . . . . . . . . . |
Data Raw: | 01 00 fe ff 03 0a 00 00 ff ff ff ff 20 08 02 00 00 00 00 00 c0 00 00 00 00 00 00 46 26 00 00 00 4d 69 63 72 6f 73 6f 66 74 20 4f 66 66 69 63 65 20 45 78 63 65 6c 20 32 30 30 33 20 57 6f 72 6b 73 68 65 65 74 00 06 00 00 00 42 69 66 66 38 00 0e 00 00 00 45 78 63 65 6c 2e 53 68 65 65 74 2e 38 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00 |
General | |
Stream Path: | \x5DocumentSummaryInformation |
CLSID: | |
File Type: | data |
Stream Size: | 244 |
Entropy: | 2.889430592781307 |
Base64 Encoded: | False |
Data ASCII: | . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . + , 0 . . . . . . . . . . . . . . H . . . . . . . P . . . . . . . X . . . . . . . ` . . . . . . . h . . . . . . . p . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . S h e e t 1 . . . . . S h e e t 2 . . . . . S h e e t 3 . . . . . . . . . . . . . . . . . W o r k s h e e t s . . . . . . . . . |
Data Raw: | fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 02 d5 cd d5 9c 2e 1b 10 93 97 08 00 2b 2c f9 ae 30 00 00 00 c4 00 00 00 08 00 00 00 01 00 00 00 48 00 00 00 17 00 00 00 50 00 00 00 0b 00 00 00 58 00 00 00 10 00 00 00 60 00 00 00 13 00 00 00 68 00 00 00 16 00 00 00 70 00 00 00 0d 00 00 00 78 00 00 00 0c 00 00 00 a1 00 00 00 02 00 00 00 e4 04 00 00 |
General | |
Stream Path: | \x5SummaryInformation |
CLSID: | |
File Type: | data |
Stream Size: | 200 |
Entropy: | 3.2820681057018666 |
Base64 Encoded: | False |
Data ASCII: | . . . . . . . . . . . . . . . . . . . . . . . . . . O h . . . + ' 0 . . . . . . . . . . . . . . @ . . . . . . . H . . . . . . . T . . . . . . . ` . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M i c r o s o f t E x c e l . @ . . . . | . # . @ . . . . + B . . . . . . . . . . |
Data Raw: | fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 e0 85 9f f2 f9 4f 68 10 ab 91 08 00 2b 27 b3 d9 30 00 00 00 98 00 00 00 07 00 00 00 01 00 00 00 40 00 00 00 04 00 00 00 48 00 00 00 08 00 00 00 54 00 00 00 12 00 00 00 60 00 00 00 0c 00 00 00 78 00 00 00 0d 00 00 00 84 00 00 00 13 00 00 00 90 00 00 00 02 00 00 00 e4 04 00 00 1e 00 00 00 04 00 00 00 |
General | |
Stream Path: | MBD0015E099/\x1CompObj |
CLSID: | |
File Type: | data |
Stream Size: | 114 |
Entropy: | 4.25248375192737 |
Base64 Encoded: | True |
Data ASCII: | . . . . . . . . . . . . . . . . . . . F & . . . M i c r o s o f t O f f i c e E x c e l 2 0 0 3 W o r k s h e e t . . . . . B i f f 8 . . . . . E x c e l . S h e e t . 8 . 9 q . . . . . . . . . . . . |
Data Raw: | 01 00 fe ff 03 0a 00 00 ff ff ff ff 20 08 02 00 00 00 00 00 c0 00 00 00 00 00 00 46 26 00 00 00 4d 69 63 72 6f 73 6f 66 74 20 4f 66 66 69 63 65 20 45 78 63 65 6c 20 32 30 30 33 20 57 6f 72 6b 73 68 65 65 74 00 06 00 00 00 42 69 66 66 38 00 0e 00 00 00 45 78 63 65 6c 2e 53 68 65 65 74 2e 38 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00 |
General | |
Stream Path: | MBD0015E099/\x5DocumentSummaryInformation |
CLSID: | |
File Type: | data |
Stream Size: | 244 |
Entropy: | 2.701136490257069 |
Base64 Encoded: | False |
Data ASCII: | . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . + , 0 . . . . . . . . . . . . . . P . . . . . . . X . . . . . . . d . . . . . . . l . . . . . . . t . . . . . . . | . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . F e u i l 1 . . . . . . . . . . . . . . . . . W o r k s h e e t s . . . . . . . . . . . |
Data Raw: | fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 02 d5 cd d5 9c 2e 1b 10 93 97 08 00 2b 2c f9 ae 30 00 00 00 c4 00 00 00 09 00 00 00 01 00 00 00 50 00 00 00 0f 00 00 00 58 00 00 00 17 00 00 00 64 00 00 00 0b 00 00 00 6c 00 00 00 10 00 00 00 74 00 00 00 13 00 00 00 7c 00 00 00 16 00 00 00 84 00 00 00 0d 00 00 00 8c 00 00 00 0c 00 00 00 9f 00 00 00 |
General | |
Stream Path: | MBD0015E099/\x5SummaryInformation |
CLSID: | |
File Type: | dBase III DBT, version number 0, next free block index 65534, 1st item "\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377" |
Stream Size: | 90976 |
Entropy: | 1.885975041684416 |
Base64 Encoded: | True |
Data ASCII: | . . . . . . . . . . . . . . . . . . . . . . . . . . O h . . . + ' 0 . . . 0 c . . . . . . . . . . P . . . . . . . X . . . . . . . d . . . . . . . p . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M i c r o s o f t E x c e l . @ . . . . ; { ) . @ . . . . Z % . } . @ . . . . . . . . . . . . . . . G . . . t b . . . . . . . . u . 2 . . . . . . . . . 2 . . . . ! . . . . . . . . . . v . . . ! . . A . . . |
Data Raw: | fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 e0 85 9f f2 f9 4f 68 10 ab 91 08 00 2b 27 b3 d9 30 00 00 00 30 63 01 00 09 00 00 00 01 00 00 00 50 00 00 00 04 00 00 00 58 00 00 00 08 00 00 00 64 00 00 00 12 00 00 00 70 00 00 00 0b 00 00 00 88 00 00 00 0c 00 00 00 94 00 00 00 0d 00 00 00 a0 00 00 00 13 00 00 00 ac 00 00 00 11 00 00 00 b4 00 00 00 |
General | |
Stream Path: | MBD0015E099/MBD0018D4CE/\x1Ole |
CLSID: | |
File Type: | data |
Stream Size: | 20 |
Entropy: | 0.5689955935892812 |
Base64 Encoded: | False |
Data ASCII: | . . . . . . . . . . . . . . . . . . . . |
Data Raw: | 01 00 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |
General | |
Stream Path: | MBD0015E099/MBD0018D4CE/\x3ObjInfo |
CLSID: | |
File Type: | data |
Stream Size: | 4 |
Entropy: | 0.8112781244591328 |
Base64 Encoded: | False |
Data ASCII: | . . . . |
Data Raw: | 00 00 03 00 |
General | |
Stream Path: | MBD0015E099/MBD0018D4CE/Contents |
CLSID: | |
File Type: | Corel Photo-Paint image, version 9, 716 x 547 RGB 24 bits, 11811024 micro dots/mm, 4 blocks, array offset 0x13c |
Stream Size: | 197671 |
Entropy: | 6.989042939766534 |
Base64 Encoded: | True |
Data ASCII: | C P T 9 F I L E . . . . . . . . . . . . . . . . 8 . 8 . . . . . . . . . . . . . . . . . . . . < . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . |
Data Raw: | 43 50 54 39 46 49 4c 45 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 d0 38 b4 00 d0 38 b4 00 00 00 00 00 00 00 00 00 04 00 00 00 00 00 01 00 94 00 00 00 3c 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |
General | |
Stream Path: | MBD0015E099/MBD002A52B4/\x1CompObj |
CLSID: | |
File Type: | data |
Stream Size: | 114 |
Entropy: | 4.219515110876372 |
Base64 Encoded: | False |
Data ASCII: | . . . . . . 0 . . . . . . . . . . . . . F ! . . . M i c r o s o f t O f f i c e E x c e l W o r k s h e e t . . . . . E x c e l M L 1 2 . . . . . E x c e l . S h e e t . 1 2 . 9 q . . . . . . . . . . . . |
Data Raw: | 01 00 fe ff 03 0a 00 00 ff ff ff ff 30 08 02 00 00 00 00 00 c0 00 00 00 00 00 00 46 21 00 00 00 4d 69 63 72 6f 73 6f 66 74 20 4f 66 66 69 63 65 20 45 78 63 65 6c 20 57 6f 72 6b 73 68 65 65 74 00 0a 00 00 00 45 78 63 65 6c 4d 4c 31 32 00 0f 00 00 00 45 78 63 65 6c 2e 53 68 65 65 74 2e 31 32 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00 |
General | |
Stream Path: | MBD0015E099/MBD002A52B4/Package |
CLSID: | |
File Type: | Microsoft Excel 2007+ |
Stream Size: | 50945 |
Entropy: | 7.631071730257267 |
Base64 Encoded: | True |
Data ASCII: | P K . . . . . . . . . . ! . E o . . . . . . . . . [ C o n t e n t _ T y p e s ] . x m l . ( . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . |
Data Raw: | 50 4b 03 04 14 00 06 00 08 00 00 00 21 00 e3 45 b7 6f 8c 01 00 00 c0 05 00 00 13 00 ce 01 5b 43 6f 6e 74 65 6e 74 5f 54 79 70 65 73 5d 2e 78 6d 6c 20 a2 ca 01 28 a0 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |
General | |
Stream Path: | MBD0015E099/MBD002A56E1/\x1CompObj |
CLSID: | |
File Type: | data |
Stream Size: | 114 |
Entropy: | 4.219515110876372 |
Base64 Encoded: | False |
Data ASCII: | . . . . . . 0 . . . . . . . . . . . . . F ! . . . M i c r o s o f t O f f i c e E x c e l W o r k s h e e t . . . . . E x c e l M L 1 2 . . . . . E x c e l . S h e e t . 1 2 . 9 q . . . . . . . . . . . . |
Data Raw: | 01 00 fe ff 03 0a 00 00 ff ff ff ff 30 08 02 00 00 00 00 00 c0 00 00 00 00 00 00 46 21 00 00 00 4d 69 63 72 6f 73 6f 66 74 20 4f 66 66 69 63 65 20 45 78 63 65 6c 20 57 6f 72 6b 73 68 65 65 74 00 0a 00 00 00 45 78 63 65 6c 4d 4c 31 32 00 0f 00 00 00 45 78 63 65 6c 2e 53 68 65 65 74 2e 31 32 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00 |
General | |
Stream Path: | MBD0015E099/MBD002A56E1/Package |
CLSID: | |
File Type: | Microsoft Excel 2007+ |
Stream Size: | 31124 |
Entropy: | 7.746149934092623 |
Base64 Encoded: | True |
Data ASCII: | P K . . . . . . . . . . ! . . p @ . . . . . . . . . [ C o n t e n t _ T y p e s ] . x m l . ( . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . |
Data Raw: | 50 4b 03 04 14 00 06 00 08 00 00 00 21 00 13 70 40 80 a3 01 00 00 e2 05 00 00 13 00 cf 01 5b 43 6f 6e 74 65 6e 74 5f 54 79 70 65 73 5d 2e 78 6d 6c 20 a2 cb 01 28 a0 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |
General | |
Stream Path: | MBD0015E099/MBD002A5E23/\x1CompObj |
CLSID: | |
File Type: | data |
Stream Size: | 114 |
Entropy: | 4.25248375192737 |
Base64 Encoded: | True |
Data ASCII: | . . . . . . . . . . . . . . . . . . . F & . . . M i c r o s o f t O f f i c e E x c e l 2 0 0 3 W o r k s h e e t . . . . . B i f f 8 . . . . . E x c e l . S h e e t . 8 . 9 q . . . . . . . . . . . . |
Data Raw: | 01 00 fe ff 03 0a 00 00 ff ff ff ff 20 08 02 00 00 00 00 00 c0 00 00 00 00 00 00 46 26 00 00 00 4d 69 63 72 6f 73 6f 66 74 20 4f 66 66 69 63 65 20 45 78 63 65 6c 20 32 30 30 33 20 57 6f 72 6b 73 68 65 65 74 00 06 00 00 00 42 69 66 66 38 00 0e 00 00 00 45 78 63 65 6c 2e 53 68 65 65 74 2e 38 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00 |
General | |
Stream Path: | MBD0015E099/MBD002A5E23/\x5DocumentSummaryInformation |
CLSID: | |
File Type: | data |
Stream Size: | 484 |
Entropy: | 3.922883556049869 |
Base64 Encoded: | True |
Data ASCII: | . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . + , D . . . . . . . . . . + , D . . . . . . . . . . . . . . . H . . . . . . . P . . . . . . . X . . . . . . . ` . . . . . . . h . . . . . . . p . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . I N V . . . . . P L . . . . . D P L - 1 . . . . . I N V ! P r i n t _ A r e a . . . . . P L ! P r i n t _ A r e a . . . . . . . . . . . . . . . . . |
Data Raw: | fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 02 00 00 00 02 d5 cd d5 9c 2e 1b 10 93 97 08 00 2b 2c f9 ae 44 00 00 00 05 d5 cd d5 9c 2e 1b 10 93 97 08 00 2b 2c f9 ae 44 01 00 00 00 01 00 00 08 00 00 00 01 00 00 00 48 00 00 00 17 00 00 00 50 00 00 00 0b 00 00 00 58 00 00 00 10 00 00 00 60 00 00 00 13 00 00 00 68 00 00 00 16 00 00 00 70 00 00 00 0d 00 00 00 |
General | |
Stream Path: | MBD0015E099/MBD002A5E23/\x5SummaryInformation |
CLSID: | |
File Type: | data |
Stream Size: | 19956 |
Entropy: | 3.056974324659501 |
Base64 Encoded: | True |
Data ASCII: | . . . . . . . . . . . . . . . . . . . . . . . . . . O h . . . + ' 0 . . . M . . . . . . . . . . P . . . . . . . X . . . . . . . d . . . . . . . t . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . y d t . . . . . . . . . 9 1 9 7 4 . . . . . . . . . . . W P S O f f i c e . . @ . . . . E . w . @ . . . . . 2 . @ . . . . . _ . . . . . . . . . . G . . . . M . . . . . . . . ? . . . . . . . . . | & . . . . . . . . . . . . . . & . . . " W M F C . . . . . |
Data Raw: | fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 e0 85 9f f2 f9 4f 68 10 ab 91 08 00 2b 27 b3 d9 30 00 00 00 c4 4d 00 00 09 00 00 00 01 00 00 00 50 00 00 00 04 00 00 00 58 00 00 00 08 00 00 00 64 00 00 00 12 00 00 00 74 00 00 00 0b 00 00 00 88 00 00 00 0c 00 00 00 94 00 00 00 0d 00 00 00 a0 00 00 00 13 00 00 00 ac 00 00 00 11 00 00 00 b4 00 00 00 |
General | |
Stream Path: | MBD0015E099/MBD002A5E23/Workbook |
CLSID: | |
File Type: | Applesoft BASIC program data, first line number 16 |
Stream Size: | 95624 |
Entropy: | 3.889652332882722 |
Base64 Encoded: | True |
Data ASCII: | . . . . . . . . . . . . . . . . . . . . . . . . . . . . . \\ . p . . . . 9 1 9 7 4 B . . . . a . . . . . . . . = . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . = . . . . . . Q | 9 . . . . . . . X . @ . . . . . . . . . . " . . . . . . . . . . . . |
Data Raw: | 09 08 10 00 00 06 05 00 ab 1f cd 07 c9 00 02 00 06 04 00 00 e1 00 02 00 b0 04 c1 00 02 00 00 00 e2 00 00 00 5c 00 70 00 05 00 00 39 31 39 37 34 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 |
General | |
Stream Path: | MBD0015E099/MBD002A6130/\x1CompObj |
CLSID: | |
File Type: | data |
Stream Size: | 94 |
Entropy: | 4.345966460061678 |
Base64 Encoded: | False |
Data ASCII: | . . . . . . e . . D E S T . . . . . . A c r o b a t D o c u m e n t . . . . . . . . . A c r o E x c h . D o c u m e n t . D C . 9 q . . . . . . . . . . . . |
Data Raw: | 01 00 fe ff 03 0a 00 00 ff ff ff ff 65 ca 01 b8 fc a1 d0 11 85 ad 44 45 53 54 00 00 11 00 00 00 41 63 72 6f 62 61 74 20 44 6f 63 75 6d 65 6e 74 00 00 00 00 00 15 00 00 00 41 63 72 6f 45 78 63 68 2e 44 6f 63 75 6d 65 6e 74 2e 44 43 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00 |
General | |
Stream Path: | MBD0015E099/MBD002A6130/\x1Ole |
CLSID: | |
File Type: | data |
Stream Size: | 64 |
Entropy: | 2.935667186688699 |
Base64 Encoded: | False |
Data ASCII: | . . . . . . . . . . . . . . . . 0 . . . . . . . . . . . . . . . . . F . . . . ! . . . . . F e u i l 1 ! O b j e c t 1 8 4 . |
Data Raw: | 01 00 00 02 08 00 00 00 00 00 00 00 00 00 00 00 30 00 00 00 04 03 00 00 00 00 00 00 c0 00 00 00 00 00 00 46 02 00 00 00 21 00 12 00 00 00 46 65 75 69 6c 31 21 4f 62 6a 65 63 74 20 31 38 34 00 |
General | |
Stream Path: | MBD0015E099/MBD002A6130/CONTENTS |
CLSID: | |
File Type: | PDF document, version 1.7 |
Stream Size: | 21760 |
Entropy: | 7.954015192696893 |
Base64 Encoded: | True |
Data ASCII: | % P D F - 1 . 7 . % . 1 0 o b j . < < . / T y p e / C a t a l o g . / P a g e s 2 0 R . / A c r o F o r m 2 4 0 R . > > . e n d o b j . 8 0 o b j . < < . / L e n g t h 2 . > > . s t r e a m . . q . . . e n d s t r e a m . e n d o b j . 9 0 o b j . < < . / L e n g t h 2 . > > . s t r e a m . . q . . . e n d s t r e a m . e n d o b j . 1 0 0 o b j . < < . / L e n g t h 3 8 . / F i l t e r / F l a t e D e c o d e . > > . s t r e a m . . x + 2 7 2 3 7 U 0 . B . . s = # . 3 |
Data Raw: | 25 50 44 46 2d 31 2e 37 0a 25 f6 e4 fc df 0a 31 20 30 20 6f 62 6a 0a 3c 3c 0a 2f 54 79 70 65 20 2f 43 61 74 61 6c 6f 67 0a 2f 50 61 67 65 73 20 32 20 30 20 52 0a 2f 41 63 72 6f 46 6f 72 6d 20 32 34 20 30 20 52 0a 3e 3e 0a 65 6e 64 6f 62 6a 0a 38 20 30 20 6f 62 6a 0a 3c 3c 0a 2f 4c 65 6e 67 74 68 20 32 0a 3e 3e 0a 73 74 72 65 61 6d 0d 0a 71 0a 0d 0a 65 6e 64 73 74 72 65 61 6d 0a 65 |
General | |
Stream Path: | MBD0015E099/Workbook |
CLSID: | |
File Type: | Applesoft BASIC program data, first line number 16 |
Stream Size: | 218908 |
Entropy: | 7.606771386739727 |
Base64 Encoded: | True |
Data ASCII: | . . . . . . . . . . . . . . . . . . . . . . . . . . . . . \\ . p . . . . B . . . . a . . . . . . . . = . . . . . . . . . . . . . . . . b . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . = . . . . ` < x - 9 . . . . . . . X . @ . . . . . . . . . . " . . . . . . . . . . . . . . . . . |
Data Raw: | 09 08 10 00 00 06 05 00 ab 1f cd 07 c1 00 01 00 06 04 00 00 e1 00 02 00 b0 04 c1 00 02 00 00 00 e2 00 00 00 5c 00 70 00 02 00 00 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 |
General | |
Stream Path: | MBD0015E09A/\x1Ole |
CLSID: | |
File Type: | data |
Stream Size: | 368 |
Entropy: | 6.3143437291346585 |
Base64 Encoded: | True |
Data ASCII: | . . . . w . T @ @ - 1 . . . . . . . . . . . . . . . y . . . K . . . . h . t . t . p . s . : . / . / . w . r . a . t . h . . . m . e . / . 5 . H . 4 . s . u . d . . . m . y N . . \\ c ] . 1 E _ < $ . . 8 z b = N P q . T # } _ c o L . A B d . . C ! 7 B 0 4 . k . % . h s ' . c J c $ E . . / J } n O - O a . % Q P 7 0 w ~ . . - @ . Q k . 8 P n T 1 & ` . f . . P . . . . . . . . . . . . . . . . . . $ . . . 4 . V . j . i . 4 . k . O . h . H . x . L . 4 . 2 . c . 3 . w . V . . . Y Q Y I S U * 9 R L e . ? r |
Data Raw: | 01 00 00 02 77 08 fd 54 40 40 2d 31 00 00 00 00 00 00 00 00 00 00 00 00 ec 00 00 00 e0 c9 ea 79 f9 ba ce 11 8c 82 00 aa 00 4b a9 0b e8 00 00 00 68 00 74 00 74 00 70 00 73 00 3a 00 2f 00 2f 00 77 00 72 00 61 00 74 00 68 00 2e 00 6d 00 65 00 2f 00 35 00 48 00 34 00 73 00 75 00 64 00 00 00 6d b7 10 f7 fc 79 4e 06 d5 0d 5c 63 89 5d c2 aa ae 8c b4 d3 20 31 45 5f 3c 92 ad af 24 ed 87 2e |
General | |
Stream Path: | Workbook |
CLSID: | |
File Type: | Applesoft BASIC program data, first line number 16 |
Stream Size: | 339337 |
Entropy: | 7.998570574743122 |
Base64 Encoded: | True |
Data ASCII: | . . . . . . . . . . . . . . . . . / . 6 . . . . . . . ! . r K 7 ( > . . i a ^ X W . r f E 0 ] ( 4 . i c M . . . . . . . . . . . . \\ . p . @ d n > > . . . L . D . 3 f N . . [ Y ] L . . Y [ a . { O . 2 . { . ' \\ . Z . . P ^ r / . ~ . L D > . * ) U . \\ . f B . . . . a . . . . . . = . . . . . l . . . v ( h Z 4 . . . _ . . . . > . . . . . . . . . . . . . . . . g = . . . " ! x 5 + B . t ! b @ . . . 9 . . . a " . . . . . . . . - . . . o . . . 1 . . . H V R . Y ) ~ . A . X . R - . T 1 . . . 6 . R 7 p q J F y . 2 M |
Data Raw: | 09 08 10 00 00 06 05 00 ab 1f cd 07 c1 00 01 00 06 04 00 00 2f 00 36 00 01 00 01 00 01 00 21 0f 72 95 4b f7 37 89 ca 28 3e 1a 93 13 69 c5 d7 61 f2 99 90 5e df 58 57 c7 07 72 b0 66 45 30 5d 98 bd 28 e7 34 c9 cc a6 fd 69 e6 63 b5 4d 18 e1 00 02 00 b0 04 c1 00 02 00 8b 2e e2 00 00 00 5c 00 70 00 40 64 c6 6e a0 8b 3e 3e e4 1b 07 fb c4 ec f4 a9 ac 94 92 a9 dd 0e 88 4c c7 06 44 17 33 66 |
General | |
Stream Path: | _VBA_PROJECT_CUR/PROJECT |
CLSID: | |
File Type: | ASCII text, with CRLF line terminators |
Stream Size: | 529 |
Entropy: | 5.275468832218868 |
Base64 Encoded: | True |
Data ASCII: | I D = " { B E D C 0 6 9 A - D F 0 0 - 4 E 2 1 - 9 F 3 5 - 0 7 4 3 C E 2 4 F 5 8 6 } " . . D o c u m e n t = T h i s W o r k b o o k / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = S h e e t 1 / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = S h e e t 2 / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = S h e e t 3 / & H 0 0 0 0 0 0 0 0 . . N a m e = " V B A P r o j e c t " . . H e l p C o n t e x t I D = " 0 " . . V e r s i o n C o m p a t i b l e 3 2 = " 3 9 3 2 2 2 0 0 0 " . . C M G = " D A D 8 3 6 7 9 F 7 7 D F 7 7 D F |
Data Raw: | 49 44 3d 22 7b 42 45 44 43 30 36 39 41 2d 44 46 30 30 2d 34 45 32 31 2d 39 46 33 35 2d 30 37 34 33 43 45 32 34 46 35 38 36 7d 22 0d 0a 44 6f 63 75 6d 65 6e 74 3d 54 68 69 73 57 6f 72 6b 62 6f 6f 6b 2f 26 48 30 30 30 30 30 30 30 30 0d 0a 44 6f 63 75 6d 65 6e 74 3d 53 68 65 65 74 31 2f 26 48 30 30 30 30 30 30 30 30 0d 0a 44 6f 63 75 6d 65 6e 74 3d 53 68 65 65 74 32 2f 26 48 30 30 30 |
General | |
Stream Path: | _VBA_PROJECT_CUR/PROJECTwm |
CLSID: | |
File Type: | data |
Stream Size: | 104 |
Entropy: | 3.0488640812019017 |
Base64 Encoded: | False |
Data ASCII: | T h i s W o r k b o o k . T . h . i . s . W . o . r . k . b . o . o . k . . . S h e e t 1 . S . h . e . e . t . 1 . . . S h e e t 2 . S . h . e . e . t . 2 . . . S h e e t 3 . S . h . e . e . t . 3 . . . . . |
Data Raw: | 54 68 69 73 57 6f 72 6b 62 6f 6f 6b 00 54 00 68 00 69 00 73 00 57 00 6f 00 72 00 6b 00 62 00 6f 00 6f 00 6b 00 00 00 53 68 65 65 74 31 00 53 00 68 00 65 00 65 00 74 00 31 00 00 00 53 68 65 65 74 32 00 53 00 68 00 65 00 65 00 74 00 32 00 00 00 53 68 65 65 74 33 00 53 00 68 00 65 00 65 00 74 00 33 00 00 00 00 00 |
General | |
Stream Path: | _VBA_PROJECT_CUR/VBA/_VBA_PROJECT |
CLSID: | |
File Type: | data |
Stream Size: | 2644 |
Entropy: | 3.9850977630535067 |
Base64 Encoded: | False |
Data ASCII: | a . . . . . @ . . . . . . . . . . . . . . . . . . . . . . . . * . \\ . G . { . 0 . 0 . 0 . 2 . 0 . 4 . E . F . - . 0 . 0 . 0 . 0 . - . 0 . 0 . 0 . 0 . - . C . 0 . 0 . 0 . - . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 4 . 6 . } . # . 4 . . . 0 . # . 9 . # . C . : . \\ . P . R . O . G . R . A . ~ . 2 . \\ . C . O . M . M . O . N . ~ . 1 . \\ . M . I . C . R . O . S . ~ . 1 . \\ . V . B . A . \\ . V . B . A . 6 . \\ . V . B . E . 6 . . . D . L . L . # . V . i . s . u . a . l . . B . a . s . i . c . . F . o . r . |
Data Raw: | cc 61 88 00 00 01 00 ff 09 40 00 00 09 04 00 00 e4 04 01 00 00 00 00 00 00 00 00 00 01 00 04 00 02 00 fa 00 2a 00 5c 00 47 00 7b 00 30 00 30 00 30 00 32 00 30 00 34 00 45 00 46 00 2d 00 30 00 30 00 30 00 30 00 2d 00 30 00 30 00 30 00 30 00 2d 00 43 00 30 00 30 00 30 00 2d 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 34 00 36 00 7d 00 23 00 34 00 2e 00 30 00 23 00 |
General | |
Stream Path: | _VBA_PROJECT_CUR/VBA/dir |
CLSID: | |
File Type: | data |
Stream Size: | 553 |
Entropy: | 6.355777360002286 |
Base64 Encoded: | True |
Data ASCII: | . % . . . . . . . . 0 * . . . . p . . H . . . . d . . . . . . . V B A P r o j e c t . . 4 . . @ . . j . . . = . . . . r . . . . . . . . . L . . i . . . . J < . . . . . r s t d o l e > . . . s . t . d . o . l . e . . . h . % . ^ . . * \\ G { 0 0 0 2 0 4 3 0 - . . . . . C . . . . . . 0 0 4 . 6 } # 2 . 0 # 0 . # C : \\ W i n d . o w s \\ S y s W O W 6 4 \\ . e 2 . . t l b # O L E . A u t o m a t i . o n . ` . . E O f f D i c E O . f . i . c E . . E . 2 D F 8 D 0 4 C . - 5 B F A - 1 0 1 B - B D E 5 E A A C 4 . |
Data Raw: | 01 25 b2 80 01 00 04 00 00 00 01 00 30 2a 02 02 90 09 00 70 14 06 48 03 00 82 02 00 64 e4 04 04 00 0a 00 1c 00 56 42 41 50 72 6f 6a 65 88 63 74 05 00 34 00 00 40 02 14 6a 06 02 0a 3d 02 0a 07 02 72 01 14 08 05 06 12 09 02 12 4c 0b 17 69 08 94 00 0c 02 4a 3c 02 0a 16 00 01 72 80 73 74 64 6f 6c 65 3e 02 19 00 73 00 74 00 64 00 6f 00 80 6c 00 65 00 0d 00 68 00 25 02 5e 00 03 2a 5c 47 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 8, 2024 15:38:23.343991995 CEST | 65437 | 443 | 192.168.2.6 | 188.114.96.3 |
Oct 8, 2024 15:38:23.344094992 CEST | 443 | 65437 | 188.114.96.3 | 192.168.2.6 |
Oct 8, 2024 15:38:23.344194889 CEST | 65437 | 443 | 192.168.2.6 | 188.114.96.3 |
Oct 8, 2024 15:38:23.344518900 CEST | 65437 | 443 | 192.168.2.6 | 188.114.96.3 |
Oct 8, 2024 15:38:23.344558001 CEST | 443 | 65437 | 188.114.96.3 | 192.168.2.6 |
Oct 8, 2024 15:38:23.823031902 CEST | 443 | 65437 | 188.114.96.3 | 192.168.2.6 |
Oct 8, 2024 15:38:23.823265076 CEST | 65437 | 443 | 192.168.2.6 | 188.114.96.3 |
Oct 8, 2024 15:38:23.828157902 CEST | 65437 | 443 | 192.168.2.6 | 188.114.96.3 |
Oct 8, 2024 15:38:23.828212023 CEST | 443 | 65437 | 188.114.96.3 | 192.168.2.6 |
Oct 8, 2024 15:38:23.828548908 CEST | 443 | 65437 | 188.114.96.3 | 192.168.2.6 |
Oct 8, 2024 15:38:23.828612089 CEST | 65437 | 443 | 192.168.2.6 | 188.114.96.3 |
Oct 8, 2024 15:38:23.829358101 CEST | 65437 | 443 | 192.168.2.6 | 188.114.96.3 |
Oct 8, 2024 15:38:23.875403881 CEST | 443 | 65437 | 188.114.96.3 | 192.168.2.6 |
Oct 8, 2024 15:38:24.233849049 CEST | 443 | 65437 | 188.114.96.3 | 192.168.2.6 |
Oct 8, 2024 15:38:24.233927011 CEST | 443 | 65437 | 188.114.96.3 | 192.168.2.6 |
Oct 8, 2024 15:38:24.233983994 CEST | 65437 | 443 | 192.168.2.6 | 188.114.96.3 |
Oct 8, 2024 15:38:24.234055042 CEST | 65437 | 443 | 192.168.2.6 | 188.114.96.3 |
Oct 8, 2024 15:38:24.456479073 CEST | 65437 | 443 | 192.168.2.6 | 188.114.96.3 |
Oct 8, 2024 15:38:24.456506014 CEST | 443 | 65437 | 188.114.96.3 | 192.168.2.6 |
Oct 8, 2024 15:38:24.458580971 CEST | 65438 | 80 | 192.168.2.6 | 72.5.42.5 |
Oct 8, 2024 15:38:24.463632107 CEST | 80 | 65438 | 72.5.42.5 | 192.168.2.6 |
Oct 8, 2024 15:38:24.463721037 CEST | 65438 | 80 | 192.168.2.6 | 72.5.42.5 |
Oct 8, 2024 15:38:24.463906050 CEST | 65438 | 80 | 192.168.2.6 | 72.5.42.5 |
Oct 8, 2024 15:38:24.469053030 CEST | 80 | 65438 | 72.5.42.5 | 192.168.2.6 |
Oct 8, 2024 15:38:32.223870993 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:32.223917961 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:32.224001884 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:32.224323988 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:32.224335909 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:32.874248981 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:32.874381065 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:32.875969887 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:32.875982046 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:32.876307964 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:32.877979994 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:32.919408083 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:32.984036922 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:32.984081030 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:32.984100103 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:32.984196901 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:32.984224081 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:32.984277964 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.071239948 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.071261883 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.071441889 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.071455002 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.071569920 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.072886944 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.072930098 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.072962046 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.072967052 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.072990894 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.073004007 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.158282042 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.158328056 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.158387899 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.158411026 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.158435106 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.158457041 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.159327984 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.159368992 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.159399986 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.159419060 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.159432888 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.159461975 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.160861969 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.160906076 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.160931110 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.160936117 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.160962105 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.160995007 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.161843061 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.161885977 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.161910057 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.161915064 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.161938906 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.161957026 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.245878935 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.245913029 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.246117115 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.246143103 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.246190071 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.246248007 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.246254921 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.246320963 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.246326923 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.246365070 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.247203112 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.247221947 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.247270107 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.247277975 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.247297049 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.247315884 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.248648882 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.248676062 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.248730898 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.248734951 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.248773098 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.249161959 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.249181986 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.249222994 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.249233007 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.249249935 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.249273062 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.250133991 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.250154972 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.250200033 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.250204086 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.250230074 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.250247955 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.251061916 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.251080990 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.251128912 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.251133919 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.251164913 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.333843946 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.333923101 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.333928108 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.333954096 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.333975077 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.334008932 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.334127903 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.334170103 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.334188938 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.334196091 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.334220886 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.334239960 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.334686995 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.334728003 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.334753990 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.334758997 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.334780931 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.334800959 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.335011005 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.335048914 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.335072994 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.335077047 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.335103035 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.335120916 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.335539103 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.335597038 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.335621119 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.335624933 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.335650921 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.335664034 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.339622974 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.339664936 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.339694023 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.339699030 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.339710951 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.339734077 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.339978933 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.340020895 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.340046883 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.340050936 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.340070963 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.340090036 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.340281010 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.340332985 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.340347052 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.340379000 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.340388060 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.340424061 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.422080040 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.422111988 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.422327042 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.422332048 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.422358036 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.422460079 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.422744036 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.422765017 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.422804117 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.422813892 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.422841072 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.423264027 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.423295021 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.423327923 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.423332930 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.423360109 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.423635006 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.423652887 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.423693895 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.423700094 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.423717022 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.424062967 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.424086094 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.424117088 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.424122095 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.424149036 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.424514055 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.424532890 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.424571991 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.424576998 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.424602032 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.424910069 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.424932957 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.424964905 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.424968958 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.424998045 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.466425896 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.509825945 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.509852886 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.510062933 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.510076046 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.510091066 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.510111094 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.510217905 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.510232925 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.510302067 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.510613918 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.510628939 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.510674953 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.510679007 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.510718107 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.511122942 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.511147022 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.511198044 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.511202097 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.511241913 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.511529922 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.511549950 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.511595011 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.511605024 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.511622906 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.511636972 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.511951923 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.511965990 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.512017965 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.512027979 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.512065887 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.512399912 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.512413025 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.512459040 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.512463093 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.512505054 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.512800932 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.512814045 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.512864113 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.512867928 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.512907982 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.597069979 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.597093105 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.597260952 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.597282887 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.597305059 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.597325087 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.597414970 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.597419977 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.597505093 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.598568916 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.598586082 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.598640919 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.598645926 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.598690033 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.600063086 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.600073099 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.600133896 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.600140095 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.600173950 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.600405931 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.600420952 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.600467920 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.600471973 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.600506067 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.600661039 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.600673914 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.600713015 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.600717068 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.600747108 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.601130009 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.601151943 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.601181030 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.601185083 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.601201057 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.601202965 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.601221085 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.601222038 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.601233959 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.601247072 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.601275921 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.684864044 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.684926987 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.684994936 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.685015917 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.685041904 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.685062885 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.685636044 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.685678959 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.685868979 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.685874939 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.685920000 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.686377048 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.686425924 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.686455965 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.686460972 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.686492920 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.686538935 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.686712980 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.686755896 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.686780930 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.686784983 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.686811924 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.686836004 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.687179089 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.687222958 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.687247992 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.687252998 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.687279940 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.687295914 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.687669039 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.687711000 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.687733889 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.687738895 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.687766075 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.687781096 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.688383102 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.688424110 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.688458920 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.688462973 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.688484907 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.688503981 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.688954115 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.688997030 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.689018011 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.689023972 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.689044952 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.689057112 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.772547960 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.772591114 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.772643089 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.772665977 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.772680044 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.772713900 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.773202896 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.773243904 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.773271084 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.773276091 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.773303986 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.773325920 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.774497986 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.774538994 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.774570942 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.774575949 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.774597883 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.774611950 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.774780989 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.774821043 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.774846077 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.774851084 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.774874926 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.774893999 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.775197983 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.775244951 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.775259972 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.775264978 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.775291920 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.775305986 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.775562048 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.775604963 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.775628090 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.775631905 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.775656939 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.775676012 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.776036978 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.776093960 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.776099920 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.776122093 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.776154041 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.776168108 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.776796103 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.776837111 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.776860952 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.776865959 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.776896000 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.776904106 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.863595963 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.863645077 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.863718987 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.863735914 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.863765955 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.863787889 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.863804102 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.863856077 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.863879919 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.863883972 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.863908052 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.863915920 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.864123106 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.864165068 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.864188910 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.864192963 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.864216089 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.864237070 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.865691900 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.865735054 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.865767956 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.865772009 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.865792990 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.865808964 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.866147041 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.866189003 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.866210938 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.866214991 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.866245031 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.866256952 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.866295099 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.866339922 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.866358995 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.866364002 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.866395950 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.866453886 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.866461039 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.866470098 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.866504908 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:33.866533041 CEST | 65440 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:33.866549969 CEST | 443 | 65440 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:36.570875883 CEST | 65441 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:36.570931911 CEST | 443 | 65441 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:36.570996046 CEST | 65441 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:36.571187973 CEST | 65441 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:36.571194887 CEST | 443 | 65441 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:37.216856003 CEST | 443 | 65441 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:37.217422962 CEST | 65441 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:37.217439890 CEST | 443 | 65441 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:37.218266010 CEST | 65441 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:37.218271017 CEST | 443 | 65441 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:37.315623999 CEST | 443 | 65441 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:37.315650940 CEST | 443 | 65441 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:37.315746069 CEST | 65441 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:37.315756083 CEST | 443 | 65441 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:37.315779924 CEST | 443 | 65441 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:37.315859079 CEST | 65441 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:37.316162109 CEST | 65441 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:37.316178083 CEST | 443 | 65441 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:37.316186905 CEST | 65441 | 443 | 192.168.2.6 | 13.107.246.60 |
Oct 8, 2024 15:38:37.316191912 CEST | 443 | 65441 | 13.107.246.60 | 192.168.2.6 |
Oct 8, 2024 15:38:46.044428110 CEST | 80 | 65438 | 72.5.42.5 | 192.168.2.6 |
Oct 8, 2024 15:38:46.044667006 CEST | 65438 | 80 | 192.168.2.6 | 72.5.42.5 |
Oct 8, 2024 15:38:46.044667006 CEST | 65438 | 80 | 192.168.2.6 | 72.5.42.5 |
Oct 8, 2024 15:38:46.049890041 CEST | 80 | 65438 | 72.5.42.5 | 192.168.2.6 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 8, 2024 15:37:47.396344900 CEST | 53 | 54573 | 162.159.36.2 | 192.168.2.6 |
Oct 8, 2024 15:37:47.947695017 CEST | 50465 | 53 | 192.168.2.6 | 1.1.1.1 |
Oct 8, 2024 15:37:47.956320047 CEST | 53 | 50465 | 1.1.1.1 | 192.168.2.6 |
Oct 8, 2024 15:38:23.011100054 CEST | 58517 | 53 | 192.168.2.6 | 1.1.1.1 |
Oct 8, 2024 15:38:23.343089104 CEST | 53 | 58517 | 1.1.1.1 | 192.168.2.6 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Oct 8, 2024 15:37:47.947695017 CEST | 192.168.2.6 | 1.1.1.1 | 0x207f | Standard query (0) | PTR (Pointer record) | IN (0x0001) | false | |
Oct 8, 2024 15:38:23.011100054 CEST | 192.168.2.6 | 1.1.1.1 | 0xfdbe | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Oct 8, 2024 15:37:20.498356104 CEST | 1.1.1.1 | 192.168.2.6 | 0xffb3 | No error (0) | s-part-0017.t-0009.t-msedge.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Oct 8, 2024 15:37:20.498356104 CEST | 1.1.1.1 | 192.168.2.6 | 0xffb3 | No error (0) | 13.107.246.45 | A (IP address) | IN (0x0001) | false | ||
Oct 8, 2024 15:37:47.956320047 CEST | 1.1.1.1 | 192.168.2.6 | 0x207f | Name error (3) | none | none | PTR (Pointer record) | IN (0x0001) | false | |
Oct 8, 2024 15:38:23.343089104 CEST | 1.1.1.1 | 192.168.2.6 | 0xfdbe | No error (0) | 188.114.96.3 | A (IP address) | IN (0x0001) | false | ||
Oct 8, 2024 15:38:23.343089104 CEST | 1.1.1.1 | 192.168.2.6 | 0xfdbe | No error (0) | 188.114.97.3 | A (IP address) | IN (0x0001) | false | ||
Oct 8, 2024 15:38:32.222832918 CEST | 1.1.1.1 | 192.168.2.6 | 0x26cd | No error (0) | s-part-0032.t-0009.t-msedge.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Oct 8, 2024 15:38:32.222832918 CEST | 1.1.1.1 | 192.168.2.6 | 0x26cd | No error (0) | 13.107.246.60 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.6 | 65438 | 72.5.42.5 | 80 | 2436 | C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 8, 2024 15:38:24.463906050 CEST | 335 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.6 | 65437 | 188.114.96.3 | 443 | 2436 | C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-08 13:38:23 UTC | 192 | OUT | |
2024-10-08 13:38:24 UTC | 1276 | IN | |
2024-10-08 13:38:24 UTC | 93 | IN | |
2024-10-08 13:38:24 UTC | 94 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.6 | 65440 | 13.107.246.60 | 443 | 2436 | C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-08 13:38:32 UTC | 219 | OUT | |
2024-10-08 13:38:32 UTC | 562 | IN | |
2024-10-08 13:38:32 UTC | 15822 | IN | |
2024-10-08 13:38:33 UTC | 16384 | IN | |
2024-10-08 13:38:33 UTC | 16384 | IN | |
2024-10-08 13:38:33 UTC | 16384 | IN | |
2024-10-08 13:38:33 UTC | 16384 | IN | |
2024-10-08 13:38:33 UTC | 16384 | IN | |
2024-10-08 13:38:33 UTC | 16384 | IN | |
2024-10-08 13:38:33 UTC | 16384 | IN | |
2024-10-08 13:38:33 UTC | 16384 | IN | |
2024-10-08 13:38:33 UTC | 16384 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.6 | 65441 | 13.107.246.60 | 443 | 2436 | C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-08 13:38:37 UTC | 207 | OUT | |
2024-10-08 13:38:37 UTC | 563 | IN | |
2024-10-08 13:38:37 UTC | 2128 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 09:37:22 |
Start date: | 08/10/2024 |
Path: | C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x540000 |
File size: | 53'161'064 bytes |
MD5 hash: | 4A871771235598812032C822E6F68F19 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 5 |
Start time: | 09:38:46 |
Start date: | 08/10/2024 |
Path: | C:\Windows\splwow64.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7cfff0000 |
File size: | 163'840 bytes |
MD5 hash: | 77DE7761B037061C7C112FD3C5B91E73 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 8 |
Start time: | 09:39:07 |
Start date: | 08/10/2024 |
Path: | C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x7ff7934f0000 |
File size: | 53'161'064 bytes |
MD5 hash: | 4A871771235598812032C822E6F68F19 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Call Graph
Graph
- Entrypoint
- Decryption Function
- Executed
- Not Executed
- Show Help
Module: Sheet1
Declaration
Line | Content |
---|---|
1 | Attribute VB_Name = "Sheet1" |
2 | Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}" |
3 | Attribute VB_GlobalNameSpace = False |
4 | Attribute VB_Creatable = False |
5 | Attribute VB_PredeclaredId = True |
6 | Attribute VB_Exposed = True |
7 | Attribute VB_TemplateDerived = False |
8 | Attribute VB_Customizable = True |
Module: Sheet2
Declaration
Line | Content |
---|---|
1 | Attribute VB_Name = "Sheet2" |
2 | Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}" |
3 | Attribute VB_GlobalNameSpace = False |
4 | Attribute VB_Creatable = False |
5 | Attribute VB_PredeclaredId = True |
6 | Attribute VB_Exposed = True |
7 | Attribute VB_TemplateDerived = False |
8 | Attribute VB_Customizable = True |
Module: Sheet3
Declaration
Line | Content |
---|---|
1 | Attribute VB_Name = "Sheet3" |
2 | Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}" |
3 | Attribute VB_GlobalNameSpace = False |
4 | Attribute VB_Creatable = False |
5 | Attribute VB_PredeclaredId = True |
6 | Attribute VB_Exposed = True |
7 | Attribute VB_TemplateDerived = False |
8 | Attribute VB_Customizable = True |
Module: ThisWorkbook
Declaration
Line | Content |
---|---|
1 | Attribute VB_Name = "ThisWorkbook" |
2 | Attribute VB_Base = "0{00020819-0000-0000-C000-000000000046}" |
3 | Attribute VB_GlobalNameSpace = False |
4 | Attribute VB_Creatable = False |
5 | Attribute VB_PredeclaredId = True |
6 | Attribute VB_Exposed = True |
7 | Attribute VB_TemplateDerived = False |
8 | Attribute VB_Customizable = True |