File name:

ORDER SHEET & SPEC.xlsm

Full analysis: https://app.any.run/tasks/16faa138-c490-4a81-85f8-a111628d3a06
Verdict: Malicious activity
Analysis date: March 25, 2025, 01:37:13
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
phishing
phish-doc
Indicators:
MIME: application/vnd.openxmlformats-officedocument.spreadsheetml.sheet
File info: Microsoft Excel 2007+
MD5:

7CCF88C0BBE3B29BF19D877C4596A8D4

SHA1:

23F0506D857D38C3CD5354B80AFC725B5F034744

SHA256:

7BCD31BD41686C32663C7CABF42B18C50399E3B3B4533FC2FF002D9F2E058813

SSDEEP:

1536:Hhh3S1cLkPROxXYvoYIZCMMV2ZX0nIcjELcE3E:0cCOxtYIEbsX0n98E

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Phishing document has been detected

      • EXCEL.EXE (PID: 4980)
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Reads security settings of Internet Explorer

      • BackgroundTransferHost.exe (PID: 5176)
      • BackgroundTransferHost.exe (PID: 7292)
      • BackgroundTransferHost.exe (PID: 4380)
      • BackgroundTransferHost.exe (PID: 6768)
    • Checks proxy server information

      • BackgroundTransferHost.exe (PID: 4380)
    • Creates files or folders in the user directory

      • BackgroundTransferHost.exe (PID: 4380)
    • Reads the software policy settings

      • BackgroundTransferHost.exe (PID: 4380)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.xlsm | Excel Microsoft Office Open XML Format document (with Macro) (45.9)
.xlsx | Excel Microsoft Office Open XML Format document (27.1)
.zip | Open Packaging Conventions container (13.9)
.ubox | Universe Sandbox simulation (9.6)
.zip | ZIP compressed archive (3.1)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2021:01:28 11:55:34
ZipCRC: 0xcdc0e5bf
ZipCompressedSize: 427
ZipUncompressedSize: 1789
ZipFileName: [Content_Types].xml

XML

Application: Microsoft Excel
DocSecurity: None
ScaleCrop: No
HeadingPairs:
  • Worksheets
  • 3
TitlesOfParts:
  • Sheet1
  • Sheet2
  • Sheet3
LinksUpToDate: No
SharedDoc: No
HyperlinksChanged: No
AppVersion: 12
LastModifiedBy: Windows
CreateDate: 2020:02:01 18:28:07Z
ModifyDate: 2020:02:01 18:32:27Z

XMP

Creator: Windows
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
146
Monitored processes
8
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start excel.exe sppextcomobj.exe no specs slui.exe no specs backgroundtransferhost.exe no specs backgroundtransferhost.exe backgroundtransferhost.exe no specs backgroundtransferhost.exe no specs backgroundtransferhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
4380"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
4980"C:\Program Files\Microsoft Office\Root\Office16\EXCEL.EXE" "C:\Users\admin\AppData\Local\Temp\ORDER SHEET & SPEC.xlsm.xlsx"C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Excel
Exit code:
0
Version:
16.0.16026.20146
Modules
Images
c:\program files\microsoft office\root\office16\excel.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ole32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\combase.dll
c:\windows\system32\gdi32.dll
5176"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
6768"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
7012C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
7172"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7292"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
7788"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
Total events
7 863
Read events
7 596
Write events
241
Delete events
26

Modification events

(PID) Process:(4980) EXCEL.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\Common\ClientTelemetry\Sampling
Operation:writeName:1
Value:
01D014000000001000B24E9A3E02000000000000000600000000000000
(PID) Process:(4980) EXCEL.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Excel\Resiliency\StartupItems
Operation:writeName:5)%
Value:
3529250074130000010000000000000025AA6F7B269DDB0100000000
(PID) Process:(4980) EXCEL.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Excel
Operation:writeName:ImmersiveWorkbookDirtySentinel
Value:
0
(PID) Process:(4980) EXCEL.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Excel
Operation:writeName:ExcelPreviousSessionId
Value:
{D2038165-101C-4B12-8F7A-0EF1ED01B18B}
(PID) Process:(4980) EXCEL.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Excel
Operation:writeName:FontInfoCache
Value:
6000000060000000F5FFFFFF0000000000000000000000009001000000000000000000205400610068006F006D00610000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000050000001B000000000000000D0000000B000000020000000200000000000000330000000000000000000000F5FFFFFF0000000000000000000000009001000000000000000000205300650067006F006500200055004900000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000060000001C000000000000000D0000000B000000020000000200000000000000330000000000000000000000F5FFFFFF000000000000000000000000BC02000000000000000000205400610068006F006D006100000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000600000020000000000000000D0000000B000000020000000200000000000000330000000000000000000000F3FFFFFF0000000000000000000000009001000000000000000000005400610068006F006D00610000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000060000002000000000000000100000000D000000030000000300000000000000330000000000000000000000F3FFFFFF000000000000000000000000E803000000000000000000005400610068006F006D00610000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000070000002600000000000000100000000D000000030000000300000000000000330000000000000000000000F1FFFFFF000000000000000000000000900100000000000000000000430061006C0069006200720069000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000080000001A00000000000000120000000E000000040000000300000000000000330000000000000000000000F3FFFFFF0000000000000000000000009001000000000000000000005300650067006F006500200055004900000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000070000002100000000000000110000000E000000030000000400000000000000330000000000000000000000F3FFFFFF000000000000000000000000BC02000000000000000000005300650067006F006500200055004900000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000080000002100000000000000110000000E000000030000000400000000000000330000000000000000000000F3FFFFFF0000000000000000000000009001000000000000000000205300650067006F006500200055004900000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000070000002100000000000000110000000E000000030000000400000000000000330000000000000000000000F3FFFFFF000000000000000000000000BC02000000000000000000205300650067006F006500200055004900000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000080000002100000000000000110000000E000000030000000400000000000000330000000000000000000000F5FFFFFF0000000000000000000000009001000000000000000000205300650067006F006500200055004900000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000060000001C000000000000000D0000000B000000020000000200000000000000330000000000000000000000F1FFFFFF000000000000000000000000900100000000000000000000430061006C0069006200720069000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000080000001A00000000000000120000000E000000040000000300000000000000330000000000000000000000F5FFFFFF0000000000000000000000009001000000000000000000205300650067006F006500200055004900000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000060000001C000000000000000D0000000B000000020000000200000000000000330000000000000000000000F5FFFFFF0000000000000000000000009001000000000000000000205400610068006F006D00610000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000050000001B000000000000000D0000000B000000020000000200000000000000330000000000000000000000F5FFFFFF000000000000000000000000BC02000000000000000000205300650067006F006500200055004900000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000060000001C000000000000000D0000000B000000020000000200000000000000330000000000000000000000F1FFFFFF000000000000000000000000900100000000000000000000430061006C0069006200720069000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000080000001A00000000000000120000000E000000040000000300000000000000330000000000000000000000F3FFFFFF000000000000000000000000BC02000000000000000000005300650067006F006500200055004900000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000080000002100000000000000110000000E000000030000000400000000000000330000000000000000000000
(PID) Process:(4980) EXCEL.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\Roaming
Operation:writeName:RoamingConfigurableSettings
Value:
DC00000000000000803A090041060100010001000000000000000000000000000000000000000000201C0000201C00008051010080510100805101008051010080F4030080F4030080F403002C01000084030000805101000000000084030000805101000A0000001E0000001E000000000000000000000080510100010000000100000000000000000000000000000000000000008D2700008D2700008D2700010000000A000000805101000000300000003000000030000000000084030000805101001E0000008403000080510100050000000500000005000000
(PID) Process:(4980) EXCEL.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\Roaming
Operation:writeName:RoamingConfigurableSettings
Value:
DC00000000000000803A0900E907030002001900010025002300F800000000000000000000000000201C0000201C00008051010080510100805101008051010080F4030080F4030080F403002C01000084030000805101000000000084030000805101000A0000001E0000001E000000000000000000000080510100010000000100000000000000000000000000000000000000008D2700008D2700008D2700010000000A000000805101000000300000003000000030000000000084030000805101001E0000008403000080510100050000000500000005000000
(PID) Process:(4980) EXCEL.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\excel\ConfigContextData
Operation:writeName:0
Value:
4D736F3A3A436865636B73756D52656769737472793A3A446174617C75696E7436345F747C2D353232313233393732353838323938383939313B456373436F6E666967526573706F6E7365446174617C7B202256657222203A2022696E7433325F747C30222C2022436F6E6649647322203A20227374643A3A77737472696E677C502D522D313039383135382D312D352C502D522D37363735372D312D322C502D522D32363134362D352D31372C502D442D32393633352D312D312C502D442D32373038372D312D392C502D522D37393638382D312D332C502D582D313035363139362D322D332C502D522D313037353533392D342D362C502D522D313036353130332D342D352C502D522D313034303537342D342D382C502D522D313032313439312D342D342C502D522D313032303733302D322D31302C502D522D313031393539312D342D342C502D522D313030343536312D342D342C64686965643636303A3434383338312C502D582D39383531382D362D392C502D582D313036313437302D322D332C502D582D313033363632312D312D352C502D582D313032313936352D312D372C502D582D313032313936382D322D332C502D582D37333633392D312D352C502D522D313037383237352D342D372C502D522D313037363531382D342D362C502D522D313036393531352D342D362C502D522D313032353434342D342D352C626C6F636B6564677261706869637361646170746572353A3437353839392C66653635313636373A3336313635382C6764696D65746166696C65633A3336383833372C37326838623835393A3238343430302C38306562633336353A3236353636392C61696764693533333A3338303136332C502D522D35383634302D312D332C502D582D37343731382D312D392C502D522D313037343034382D362D372C502D522D33353039392D322D342C6175656E613732343A3537373735332C502D522D313038313433312D382D362C502D522D313035333437382D382D352C502D522D33343834332D342D362C502D582D37313237342D312D372C502D522D33333832322D31342D36362C502D522D34353438332D31362D35332C502D522D35303731372D31382D36302C502D522D38373538372D342D342C502D522D37353036392D312D332C502D522D37353030312D312D332C502D522D36383135322D31382D32312C502D522D35323331362D31382D33372C502D522D34393136322D31382D31332C502D522D34393136312D31382D31332C502D522D34303235332D362D31392C502D522D34303235342D362D31382C502D522D33353430312D362D372C502D522D33323130372D32322D32322C636C70726F3130353A3436363736322C502D582D3130393138392D312D352C502D582D313030333535362D312D352C502D582D3130393137362D312D392C502D522D35323331352D31382D32362C502D522D32343938302D382D34382C502D522D31383237392D322D36352C63753637333A3332353936392C63756973663436343A3434363635342C63756973663833383A3333303731382C502D582D313033363930382D312D332C502D522D3131333931352D382D372C502D522D35323938322D31382D33342C502D522D35313134352D322D372C67356234623530373A3238363035352C502D582D313031323533332D312D352C502D522D313036393430352D342D382C502D522D313035303139342D33322D32312C502D522D34313034362D32322D37322C64696173793933323A3237333238302C502D582D313037373139382D322D352C502D582D313034383430382D322D352C502D582D38353335392D312D31332C502D582D39353537332D312D392C502D582D38393031322D312D31312C502D522D313036313635312D382D362C502D522D313034323432302D342D332C502D522D313033363136342D342D372C502D522D3131333530382D382D362C502D522D39353631362D382D352C502D522D37393631362D312D332C502D522D37373632312D312D332C502D522D37373230342D312D332C502D522D37363130372D312D332C502D522D37343333342D312D332C502D522D37343433392D312D332C502D522D37333634322D312D332C502D522D36383933382D312D362C502D522D36323837352D322D342C502D522D36303537392D322D322C502D522D36303333332D312D332C502D522D35383130372D322D322C502D522D35353734332D312D332C502D522D35313935382D312D352C502D522D33383038352D31322D392C502D522D33353338392D31382D33382C75736570726570726F63743A3337333738382C7573657632656E64706F696E7474726561746D656E743A3333333939332C6E617469766577696E333272646C3A3138363734342C646F63736C707077696E33323A3430343537382C646F6373686F6D6570616765736561726368656E61626C65616767726567617465646D7275736561726368736F757263653A3137353733392C502D522D313033343136392D31302D372C502D582D313436343837312D322D352C502D582D313435363236342D322D332C502D582D313431383138302D322D332C502D582D313431363132392D312D352C502D582D313331353136322D322D332C502D582D313236393032362D322D332C502D582D313234393332382D312D332C502D582D313233323837372D312D332C502D582D313030303239322D312D372C502D582D313034323435382D342D31312C502D582D313135393239312D322D332C502D582D313135373831312D322D332C502D582D313135303237342D322D332C502D582D313032333439332D322D31312C502D582D313032313434302D312D352C502D582D313032373230362D322D352C502D582D313038313332322D312D372C502D582D313031393637342D312D352C502D582D313034313432352D322D372C502D582D37323936342D312D392C502D582D37323332382D312D372C502D582D313035363933302D332D31352C502D582D313037383537362D322D332C502D582D313036393832302D322D352C502D582D313036323132382D312D352C502D582D313034383637302D312D372C502D582D313031393636352D312D372C502D582D313036323531312D322D332C502D582D313036303536312D312D352C502D582D313035393837302D322D332C502D582D313035383337332D322D352C502D582D313035393131312D312D332C502D582D38303734322D312D31312C502D582D39333738372D332D31312C502D582D313035363137372D322D332C502D582D313035353636352D322D352C502D582D313035363036372D322D332C502D582D313035353738392D312D352C502D582D313034393638362D312D352C502D582D313034333733382D332D392C502D582D313032363930312D322D352C502D582D313034363138332D322D332C502D582D313033373830322D322D352C502D582D313034303331392D312D352C502D582D313034313630332D322D332C502D582D313034313035372D312D332C502D582D313033393235332D312D352C502D582D37393936312D312D372C502D582D313033383739352D322D332C502D582D313033383739302D322D332C502D582D313033383735362D312D332C502D582D313033373637312D312D352C502D582D313033373835322D322D332C502D582D313033363537382D322D332C502D582D313033333335362D322D332C502D582D3130373034372D312D372C502D582D38343334372D312D352C502D582D313031393934302D312D332C502D582D313030333739312D312D352C502D582D313031383338382D312D352C502D582D313031383237362D322D332C502D582D313030333932302D332D32352C502D582D313031363132392D312D352C502D582D3130333035322D312D352C502D582D3131343339332D332D31392C502D582D3131313730312D332D31312C502D582D313030363637392D312D392C502D582D36343933362D312D392C502D582D39323439332D312D372C502D582D3131343532302D312D352C502D582D3130383431322D312D332C502D582D39393034342D312D332C502D582D39383631382D312D332C502D582D39363134312D312D332C502D582D38343430392D312D352C502D582D38373131322D312D332C502D582D38363633372D312D332C502D582D38343234392D312D352C502D582D38303233382D312D352C502D582D37353337342D312D352C502D582D37363030392D312D332C502D582D36383139352D312D31312C502D452D32383637372D322D332C502D522D313436353034352D31342D31322C502D522D313435393737322D31342D31392C502D522D313431383833332D31342D31362C502D522D313431363531332D31332D32302C502D522D313337383337342D31342D31322C502D522D313236393033392D31342D31362C502D522D313236303430392D342D362C502D522D313234393334352D31332D31352C502D522D313233323838302D31332D31312C502D522D313135393330342D31342D31332C502D522D313135373833362D31342D31352C502D522D313135303337392D31342D31342C502D522D313134363333342D31322D352C502D522D313134353937372D31312D362C502D522D313134353237352D392D372C502D522D313132373630302D382D382C502D522D313039393738332D362D352C502D522D313039303934352D382D372C502D522D313037333431372D382D362C502D522D313036343634332D362D362C502D522D313036313333312D382D362C502D522D313034373531352D382D332C502D522D313033393739372D382D392C502D522D313030393438372D342D332C502D522D3131373139302D362D342C502D522D3131313931322D362D342C502D522D3131313534372D342D362C502D522D3130373639332D342D362C502D522D39303834382D382D342C502D522D37343731352D312D362C502D522D36363634302D31382D32342C502D522D36363633392D31382D322C502D522D36363135352D31382D362C502D522D36343730322D33302D31302C502D522D36343536342D31382D342C502D522D36333939372D322D332C502D522D36333437342D31382D362C502D522D36313632382D32382D382C502D522D36303138382D31382D382C502D522D35383536312D31382D33302C502D522D35353132322D382D382C502D522D35363037392D31382D32342C502D522D35353235342D31382D33392C502D522D35343337342D312D342C502D522D35333930352D31382D392C502D522D35333230392D31382D372C502D522D35313033362D31382D332C502D522D35303235352D31302D392C502D522D34363536332D31382D31342C502D522D34363238382D31382D362C502D522D34343932392D43372D34302C502D522D34353331342D31302D31362C502D522D34353039312D31382D32362C502D522D34343730332D31382D32362C502D522D34343034332D31382D32372C502D522D34303832382D322D332C502D522D33323137302D32302D32322C502D522D33313431352D312D342C502D522D33303534302D312D352C502D522D33303533392D342D372C502D522D33303533342D382D31302C502D442D36313731372D392D312C502D442D35303631322D332D322C502D442D35303631312D312D312C64326234323134313A3638363335312C6A663035353130343A3639343534312C616E616C797A656461746166616C6C6261636B746F656C73652D74726561746D656E743A3633343830372C33366364333739393A3633343838352C6175676C6F6F70616E616C797A6564617461776F726B666C6F7774696D656F75742D74726561746D656E743A3632323934362C6C6C6D63686172747265636F2D74726561746D656E74333A3631343632322C37396331633337303A3631343632332C31326338313937383A3532313034392C65786D69633434393A3531333732352C786C732D6175676D656E746174696F6E6C6F6F70717569636B73617665656E61626C65642D74726561746D656E743A3530313031392C7573657632617574682D74726561746D656E743A3437373131352C616E616C797A656461746174696D656F75742D74726561746D656E743A3437383431322C786C732D657863656C736861726564636F70696C6F742D74726561746D656E743A3437353838352C69353962303139393A3439353832392C313039666A3634323A3239383231332C68646335343630323A3433323136302C38343634303430373A3439353831312C65783130363A3435343436352C67666962673436373A3435343330362C65787573653631353A3338303232302C6578696E733839373A3137303631342C65316738693134333A3439353831372C37393332313738393A3335353439302C696E7369676874732D6C6F677265636F6D6D656E646174696F6E737369676E616C736465736B746F706F6E3A3338343232322C34366736373537383A3434383438372C306A3436363635303A3435343933322C65783532333A3333373438332C63656C6C61637469766174656166746572636F6D6D69746576656E747468726573686F6C642D7472746D743A3431383336312C696D706F727466726F6D64796E616D6963617272617976323A3332333338392C69363666683238363A3334343235322C6561746D6D74663A3431383239322C336A6768393438383A3337353232372C6578706F773334343A3337353535352C65787069766F746E6F6E64657374727563746976656175746F67726F75703A3338373137392C69393268333737303A3333363131342C696A6363623535363A3332393931342C66693865673832383A3332333432322C35373933333933353A3431323736362C33666A30683638343A3337363639392C39623732653937383A3433393733352C786C2D7175657279656E6473657373696F6E7665746F6469727479626F6F6B2D74726561746D656E743A3334353036392C7573656269666C706772616463616368652D74726561746D656E743A3433343933362C6A656237663730353A3432373334352C34356532633836303A3335363338362C37373764383935333A3336303437302C69336867673530333A3432373334312C353037646A3533353A3237383830332C657861766F3833333A3234393839332C61336938303236393A3430353438322C67623437683331353A3430353437312C63686230663439303A3337373433302C66697874726B70616E776169743A3431333237332C627573696E6573736261725F6F6E3A3336303439322C35666869353632333A3432373432322C736D617274726563616C632D74726561746D656E743A3433313131322C65786C6F613433373A3434333435392C65786578633139343A3435333431392C646670773332693A3435393534342C7573657461626C657265636F6D6C3A3330353632312C65787468723137343A3538313131332C657837313563663A3337393138372C6A676630383830363A3239343035392C6578616972636D646C6973743A3236363136392C6578636F613334323A3230393531322C65783236363A3431383430302C65786F63733535383A3638333634332C65783634393A3434303737322C696E7369676874732D7573656265747465727375676765737465647175657374696F6E733A3232303839312C65787269633234323A3230383330362C6578656E613334343A3331303230362C65786C6F673134353A3331373938382C6D6F6465726E62726F777365726F617574686469616C6F673A3230383934332C706F77657271756572796E657772656672657368616E6464656C657465766261636F6D6D616E64733A3139333132312C65786973723434383A3230383933342C65786F63733430393A3336353635362C65783664343634353A3138323731352C706F77657271756572797461736B70616E65706572666F726D636C65616E75706E6F72656E6465723A3131393138302C6578696E733436333A3132303736352C69646561737072656C6F6164696E73657274746162656E61626C65643A3235363437392C6578696E733539393A3130363036382C65787573653337333A38373939392C65786670693634323A3130353133342C616E616C797A656461746166616C6C6261636B746F656C73652D74726561746D656E743A3633343830372C6175676C6F6F70616E616C797A6564617461776F726B666C6F7774696D656F75742D74726561746D656E743A3632323934362C6C6C6D63686172747265636F2D74726561746D656E74333A3631343632322C7573657632617574682D74726561746D656E743A3437373131352C616E616C797A656461746174696D656F75742D74726561746D656E743A3437383431322C786C732D657863656C736861726564636F70696C6F742D74726561746D656E743A3437353838352C65783130363A3435343436352C65786578633139343A3435333431392C7573656269666C706772616463616368652D74726561746D656E743A3433343933362C502D582D313234303832332D312D332C502D452D33383233312D43312D342C502D522D313234353636322D31352D342C502D522D39343536302D31342D31322C502D522D39343138392D31342D31332C502D522D39333838322D31342D32362C502D522D36313134372D4331372D322C502D522D35343732382D31362D32332C502D522D35343639382D31362D31362C502D522D35343635382D31382D31392C502D522D34303034392D372D32392C502D522D33383330362D4331372D332C502D522D33343031392D342D332C77696E333264657669636563616E6172793A3534313438332C77696E333264657669636563616E6172793A3534313438332C502D582D313035313539312D312D352C502D582D313034363431342D312D372C502D582D313035383536382D312D352C502D582D313032373535312D322D372C502D582D313036363637382D332D372C502D582D313035363938332D322D332C502D582D313035343132322D322D372C502D582D313035333332312D312D392C502D582D313034393633392D322D372C502D582D313030373237342D332D31372C502D582D313030373237352D31332D34352C502D582D38353839362D312D31392C502D582D39313739302D312D352C502D582D313033383135362D312D332C502D582D313033373134382D322D332C502D582D313033353837312D312D332C502D582D313032383535342D312D332C502D582D313031343433312D312D372C502D582D313030353434352D312D352C502D582D313031313433352D312D332C502D582D3131363131352D312D392C502D582D3130373539352D312D352C502D582D3131363939302D312D352C502D582D38363238322D312D372C502D582D36313130322D332D31312C502D582D35313236322D312D31312C502D582D35323539312D312D31312C502D582D39363935362D312D372C502D582D39383636352D312D392C502D582D39383635352D312D352C502D582D38343436342D312D352C502D582D38343633332D312D332C502D582D35343335382D312D372C502D582D35333937352D332D392C502D582D36393138392D312D372C502D582D35363237342D312D392C502D582D36333133342D312D372C502D582D35383637382D312D352C502D582D35353833322D312D362C502D582D35363134372D312D352C502D582D35363135342D312D352C502D582D35343231322D312D352C502D522D313535343133302D342D352C502D522D313535343132372D342D352C502D522D313535343132322D342D362C502D522D313037343833392D382D35
(PID) Process:(4980) EXCEL.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\excel\ConfigContextData
Operation:writeName:ChunkCount
Value:
uint64_t|0
(PID) Process:(4980) EXCEL.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\excel\ConfigContextData
Operation:writeName:0.1
Value:
2C502D522D313037343430372D382D352C502D522D313037343033302D382D342C502D522D313037323332362D382D362C502D522D313036323835322D382D392C502D522D313035333236392D382D352C502D522D39353038322D382D352C502D522D39333937302D382D342C502D522D36393036352D312D332C502D522D35393139332D312D332C502D522D34353630392D31342D362C502D522D34353137372D31382D32342C502D522D34353139372D322D362C502D522D34303938302D31382D31362C502D522D33393032392D352D31382C502D522D33353136352D322D372C502D522D32393830392D312D372C502D522D32363936382D332D392C502D522D31383432352D382D36322C502D522D31383432362D352D33302C502D522D31383432342D342D33342C502D442D313130393930372D342D31322C686E6C6162656C3A3630333036372C37343261623432323A3434393633312C646A656366383539743A3336363731382C37313567683537333A3338303334362C67343568623831303A3335333936332C66303366633135743A3334343233392C766563746F72636C6F636B656E61626C65643A3333343933342C64656661756C74746F6F6462666F726E657766696C653A3334383232352C67386968663539343A3431393233312C686E656469746F72733A3531383233342C356D696E31306D696E5F31306D696E6772616365706572696F643A3531373738392C66696C69733436363A3733363730322C66696D6F633234383A3139333439312C68617070793038323332322D313A3339383331332C63366567663438343A3333343231392C6D6F7665636C6F636B64617461746F657068656D6572616C73746F7265666F726F63733A3239353138352C68617070793037323132322D313A3335363237332C62657474657262726561646372756D62733A3439303833362C666173617263686976616C3A3333303738332C66697365733932313A3234313639392C6669616C6C3139383A3439383838372C66696261633936373A3630383537312C66696F63733230303A3434393439382C66696973773136313A3331373630342C66697465733231373A3136313436382C66697265663334363A33343532352C66696D6F633538393A32383937392C66697061723833393A3139313036322C6772617068617069666F726F64656E61626C6564726F6C6C6F75743A3339343135362C6F6E656472697665636F6E76657267656E6365656E6C69676874656E6564726F6C6C6F75743A3135393033382C66696F6D693239333A3131383038312C6669736B693232353A3439383837342C6669656E613934373A33303633352C66697374613430373A36313032372C6669656E613930333A36353934342C66696461763236353A35353033352C66696361633834313A34393636342C6669656E613431353A33383738302C6669656E613439303A33343138312C72656D6F74656D6F76656465766963653A34323530302C6669656E613237363A34313030342C6669656E613338313A34393939372C502D582D313032303335332D312D372C502D522D313233363533302D382D322C502D522D313037383537312D31382D382C502D522D313034363334302D31382D31352C502D522D313033333537392D31382D31312C502D522D313033343131382D31382D32302C502D522D313032363335342D31382D32312C502D522D35333534352D342D352C502D522D34393733362D362D32322C502D522D33303038352D312D392C502D522D32353135372D382D31342C502D522D32343336332D362D31332C502D522D31393831342D312D36322C502D522D31393031342D312D32362C502D522D31393031322D312D35372C666C656E613231343A3532363832342C666C656E613231343A3532363832342C502D582D313032343434382D312D332C30356269353338323A3430333333312C502D582D313035363435362D322D31312C502D582D313031383536342D332D392C502D582D313032303539372D312D372C502D582D313030393332392D312D372C502D582D313031313434322D312D31312C502D582D313031393633322D312D332C502D582D313031353535342D312D352C502D582D313031303331342D312D352C502D582D3130383336342D312D332C502D582D37373734322D312D352C502D582D38363339352D312D352C502D582D38343332312D312D352C502D582D35303232302D312D332C502D582D34393733302D312D332C502D522D313034333838352D362D362C502D522D313031343435322D382D382C502D522D36343834312D32322D31352C502D522D36333130302D32382D31302C502D522D35323033382D32382D31382C502D522D33363638332D31382D34302C502D522D34303939302D31322D31352C502D522D33353937322D322D352C502D522D33353537322D31342D332C502D522D33323734342D31342D31352C502D522D33323734312D33322D31362C502D522D32383735312D322D32302C69693435373531323A3434393137382C6272616B696E67736B703A3338383633312C6772616C743139333A3431313231352C6772616C743232323A3334353534372C67726766783930363A3432333930352C67723233343A3433343331362C6772736B693435353A3537383535332C67723331323A3631333334312C67723337303A3538333038372C677264656C3334373A3132373632382C67727376673936303A3435323639302C67727573653434343A3132343039312C67727573653438383A3537303335382C677269636F3430363A31393737372C502D582D3130353838392D312D352C32346139333336353A3134373734372C502D522D35303432392D31382D382C502D522D33363533392D31302D352C502D522D32343038342D312D31362C502D522D32333339312D312D392C502D582D37353232322D32322D37352C502D582D313034393232352D312D332C502D582D313033333336302D312D352C502D582D313033333335352D312D332C502D582D313031313137332D312D352C502D522D313434353932342D382D362C502D522D313130313038312D382D352C502D522D313037373631302D382D352C502D522D313032363534322D382D342C502D522D313032313732352D31382D34392C502D522D35333432312D32382D31342C502D522D34303437352D32382D32382C502D522D33353938352D31342D32332C502D522D33323030342D322D352C65786F6F6E6C7963663A3339383433372C39373935633332303A3335393832302C32646262623537393A3238363232352C69383364613438393A3338383033382C69643539323A3238383731342C502D582D38383033352D312D352C6C616C616E3233313A3134303738312C502D582D313237363530392D312D352C502D582D313031393632392D332D31362C502D582D38353734312D312D31372C502D582D3131333530312D322D382C502D582D3130303236322D312D31312C502D582D3130333738362D312D332C502D582D37383534362D312D352C502D522D313238303432352D31332D31372C502D522D36313234382D31382D372C502D522D35313939352D31382D32382C502D522D35323030302D33302D32382C502D522D34323839362D37342D3134312C69306437363937303A3539383638392C646F63756D656E747461736B756977696E6D61637778703A3432323532322C68617070793036303732312D313A3233323730342C6C656D69633530353A3230373133372C6C653430303A3333353032302C6C656973753732343A3631303738342C736572706C6574646174617365617263683A3132393239362C502D582D313034343531342D322D372C502D582D313036313732332D322D352C502D582D313037363235322D312D362C502D582D313034393634392D322D352C502D582D313034373731352D322D372C502D582D313031343139352D342D31392C502D582D313032363133312D322D352C502D582D313032373931332D312D31312C502D582D313031373734352D382D31342C502D582D38303736372D312D33372C502D582D3130383634332D322D372C502D582D313030393034382D312D392C502D582D39353630352D322D332C502D522D313035383637352D382D342C502D522D313033363537362D342D342C502D522D39383131302D342D352C502D522D37393936332D312D322C502D522D36303831362D31302D31392C502D522D35313736342D312D342C502D522D34323339322D322D342C502D522D33393037332D312D352C70697063687962726964743A3333363236352C326766396A3631383A3336323439302C396A6734633839333A3335373434342C34676839653230353A3438333737382C363135316A3631333A3434373631392C67643868383735353A3331373939302C6A6A3035303832373A3234353136322C61306537323236393A3332323039342C37673633363833323A3236383639382C65396268363531353A3234343439392C37366534673937353A3332343937392C6C693533303A3537313939352C67306864303232313A3435303335352C502D522D313132333337362D31302D31342C502D522D313030393835352D31322D31342C502D522D39383835362D31382D34382C502D522D313036313233392D382D362C502D522D34333438392D33302D31352C502D522D33383431302D31322D32332C502D582D313239313234362D322D332C502D582D313232393336302D332D31352C502D582D39323634342D312D392C502D582D37373133362D312D32372C502D582D313032373135362D312D372C502D582D313030363136382D312D352C502D582D313031323935302D342D372C502D582D313037343533362D312D332C502D582D313036363534362D312D31332C502D582D38393837382D312D352C502D582D313035313633372D322D352C502D582D313035303636352D332D372C502D582D313034333232322D312D31302C502D582D313033303234352D312D352C502D582D313034313735362D322D352C502D582D313033393334372D322D31312C502D582D313033393537362D322D332C502D582D313031393538312D312D332C502D582D313031343837382D312D392C502D582D313031333031362D312D332C502D582D313030363137342D312D352C502D582D38333832342D312D332C502D582D35313735392D312D332C502D522D313536353432382D322D332C502D522D313234393337302D342D352C502D522D313039343131352D342D342C502D522D313038393139322D362D352C502D522D313031373036362D342D352C502D522D3131373934312D342D342C502D522D35393533342D312D332C502D522D35343535372D312D332C502D522D33373630332D332D362C63683337313137393A3630303339362C656E61626C656D616E6966657374786D6C7369676E6174757265766572696669636174696F6E72656C696162696C697479323A3535323631322C656E61626C656D616E6966657374786D6C7369676E6174757265766572696669636174696F6E3A3237343939302C6578706572696D656E746174696F6E7364787072656C6F61643A37373732392C31323568373933353A3335313834372C6F656669723430393A3335313735352C6F65736574757064656C697665727966616C6C6261636B333A3434353037352C39623864613935353A3434393932342C62656C6F776F70656E646976696465723A3534323535372C6F6575696C3832303A3332363132342C33633867643634383A3436343939302C6F65656E61626C656F73666964656E746974796D616E616765723A3434393931392C6F656D69633134303A3433323035332C34633668643237393A3436333732312C67623038643735323A3239323132322C64336769653536343A3238333835332C39396631643631363A3238333835342C6F656D69633633393A3339373735332C6F653539383A3339313531302C6F65616C6C3431393A3431343537312C6F65616C6C3834333A3337353838372C6F65636F6F3133333A3336313137322C6F656D61633335383A32303530322C502D522D37313336302D31382D31392C502D582D37363535352D312D332C6F6E6D61703336363A38313734302C502D442D313437363534302D312D332C502D442D313033303630312D332D332C502D442D313135373731372D312D332C502D442D313134393433362D312D332C502D442D313133313332392D362D372C502D442D313131303935362D342D332C502D442D313038343536352D332D332C502D442D313037333031342D352D332C502D442D313033373534312D372D362C502D442D313033333339312D322D342C502D442D313033313436302D312D332C502D442D313033313035302D342D332C502D442D313033313032322D312D332C502D442D313033313031382D312D332C502D442D313033313031322D312D332C502D442D313033303936342D312D332C502D442D313033303936332D312D332C502D442D313033303935362D312D332C502D442D313033303932382D312D332C502D442D313033303932372D312D332C502D442D313033303932362D312D332C502D442D313033303932332D322D332C502D442D313033303932322D322D332C502D442D313033303932302D322D332C502D442D313033303931382D322D332C502D442D313033303931362D322D332C502D442D313033303931342D322D332C502D442D313033303931322D322D332C502D442D313033303931302D322D332C502D442D313033303930382D322D332C502D442D313033303930362D322D332C502D442D313033303930342D322D332C502D442D313033303930322D322D332C502D442D313033303930302D322D332C502D442D313033303839382D322D332C502D442D313033303839362D322D332C502D442D313033303839332D322D332C502D442D313033303839312D322D332C502D442D313033303838392D322D332C502D442D313033303838372D322D332C502D442D313033303838352D322D332C502D442D313033303838332D322D332C502D442D313033303838312D322D332C502D442D313033303837392D322D332C502D442D313033303837372D322D332C502D442D313033303837362D322D332C502D442D313033303837352D322D332C502D442D313033303837332D332D332C502D442D313033303837322D322D332C502D442D313033303837312D322D332C502D442D313033303837302D322D332C502D442D313033303836392D322D332C502D442D313033303836382D322D332C502D442D313033303836372D322D332C502D442D313033303836362D322D332C502D442D313033303836352D322D332C502D442D313033303836342D322D332C502D442D313033303836322D322D332C502D442D313033303836302D322D332C502D442D313033303835382D322D332C502D442D313033303835362D322D332C502D442D313033303835342D322D332C502D442D313033303835322D322D332C502D442D313033303835302D322D332C502D442D313033303834382D322D332C502D442D313033303834372D322D332C502D442D313033303834362D322D332C502D442D313033303834342D322D332C502D442D313033303834322D322D332C502D442D313033303834312D322D332C502D442D313033303834302D322D332C502D442D313033303833382D322D332C502D442D313033303833362D322D332C502D442D313033303833342D322D332C502D442D313033303833322D322D332C502D442D313033303833302D322D332C502D442D313033303832382D322D332C502D442D313033303832362D322D332C502D442D313033303832342D322D332C502D442D313033303832322D322D332C502D442D313033303831392D322D332C502D442D313033303831362D322D332C502D442D313033303831322D322D332C502D442D313033303831312D322D332C502D442D313033303831302D322D332C502D442D313033303830382D322D332C502D442D313033303830362D322D332C502D442D313033303830332D322D332C502D442D313033303830312D322D332C502D442D313033303830302D322D332C502D442D313033303739392D322D332C502D442D313033303739382D322D332C502D442D313033303739372D322D332C502D442D313033303739362D322D332C502D442D313033303739352D322D332C502D442D313033303739342D322D332C502D442D313033303739332D322D332C502D442D313033303739322D322D332C502D442D313033303739312D322D332C502D442D313033303738392D322D332C502D442D313033303738372D322D332C502D442D313033303738362D322D332C502D442D313033303738352D322D332C502D442D313033303738332D322D332C502D442D313033303738312D322D332C502D442D313033303737392D322D332C502D442D313033303737372D322D332C502D442D313033303737352D322D332C502D442D313033303737332D322D332C502D442D313033303737312D322D332C502D442D313033303736392D322D332C502D442D313033303736372D322D332C502D442D313033303736352D322D332C502D442D313033303736332D322D332C502D442D313033303736312D322D332C502D442D313033303736302D322D332C502D442D313033303735392D322D332C502D442D313033303735382D322D332C502D442D313033303735372D322D332C502D442D313033303735362D322D332C502D442D313033303735352D322D332C502D442D313033303735332D322D332C502D442D313033303735312D322D332C502D442D313033303734392D322D332C502D442D313033303734372D322D332C502D442D313033303734352D322D332C502D442D313033303734332D322D332C502D442D313033303734302D332D332C502D442D313033303733382D322D332C502D442D313033303733372D322D332C502D442D313033303733362D322D332C502D442D313033303733342D322D332C502D442D313033303733322D322D332C502D442D313033303733302D322D332C502D442D313033303732382D322D332C502D442D313033303732362D322D332C502D442D313033303732342D322D332C502D442D313033303732322D322D332C502D442D313033303731392D322D332C502D442D313033303731372D322D332C502D442D313033303731352D322D332C502D442D313033303731332D322D332C502D442D313033303731322D322D332C502D442D313033303731312D322D332C502D442D313033303730392D322D332C502D442D313033303730382D322D332C502D442D313033303730372D322D332C502D442D313033303730362D322D332C502D442D313033303730352D322D332C502D442D313033303730342D322D332C502D442D313033303730332D322D332C502D442D313033303730322D322D332C502D442D313033303730312D322D332C502D442D313033303639392D322D332C502D442D313033303639372D322D332C502D442D313033303639362D322D332C502D442D313033303639352D322D332C502D442D313033303639332D322D332C502D442D313033303639312D322D332C502D442D313033303639302D322D332C502D442D313033303638392D322D332C502D442D313033303638372D322D332C502D442D313033303638352D322D332C502D442D313033303638332D322D332C502D442D313033303638312D322D332C502D442D313033303637392D322D332C502D442D313033303637372D322D332C502D442D313033303637352D322D332C502D442D31303330363733
Executable files
0
Suspicious files
26
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
4380BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\96f374e7-d953-43e6-bc01-486dce8c2efc.down_data
MD5:
SHA256:
4980EXCEL.EXEC:\Users\admin\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\AB048A6D-BABD-47D8-8B59-061FAAC84800xml
MD5:1B9D93DB12778F9E85135183FB6BBEC0
SHA256:38D8F4B2959106931407AC30A84AA2C5E76C25F2ED25921B96E85FBFACF3830E
4380BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\Content\26C212D9399727259664BDFCA073966E_F9F7D6A7ECE73106D2A8C63168CDA10Dbinary
MD5:4872BABAF39AA62B8D32695EBB7E9173
SHA256:2EE85DF86EE29BBEB3DCA81AA29B6DE204F605A2769B84C728A329178A2D0999
4980EXCEL.EXEC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_CBDCCBFE4F7A916411C1E69BDD97BB04binary
MD5:0BBEDBE65D529A83D458D6526145E2AD
SHA256:F5E7FDED7887B5235D7A33796629D2A057CAED455093A0D8ADAD0E9E2B2FE3D6
4980EXCEL.EXEC:\Users\admin\AppData\Local\Microsoft\TokenBroker\Cache\089d66ba04a8cec4bdc5267f42f39cf84278bb67.tbresbinary
MD5:A1558EAAC2697E072EE01E14E8C521A2
SHA256:63045014C4EEBD80FB2CF76C51BCB8EEAE090BCB567EDA4D84709625930D3A16
4380BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\MetaData\26C212D9399727259664BDFCA073966E_F9F7D6A7ECE73106D2A8C63168CDA10Dbinary
MD5:9D27C1A251B5D10E267663862814F631
SHA256:1792BAEA5730E00FA80FADFBBDFBC68B0FA21C5BCBCEA712832E421D1F558B11
4380BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\96f374e7-d953-43e6-bc01-486dce8c2efc.7299dba7-ca83-4b2d-ba6b-f60f14eb0c02.down_metabinary
MD5:0D7366076BE2207ED06D36301A394BC3
SHA256:6BE4992C9C44F30C6F9A314A34B5D70336724A253CDBB3CF23420A2F6F063BB2
4380BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\94bff3b9-460d-408f-bc6d-8b7648d4fd94.7299dba7-ca83-4b2d-ba6b-f60f14eb0c02.down_metabinary
MD5:0D7366076BE2207ED06D36301A394BC3
SHA256:6BE4992C9C44F30C6F9A314A34B5D70336724A253CDBB3CF23420A2F6F063BB2
4980EXCEL.EXEC:\Users\admin\AppData\Local\Temp\Diagnostics\EXCEL\App1742866654372696400_D2038165-101C-4B12-8F7A-0EF1ED01B18B.log
MD5:
SHA256:
4980EXCEL.EXEC:\Users\admin\AppData\Local\Microsoft\TokenBroker\Cache\56a61aeb75d8f5be186c26607f4bb213abe7c5ec.tbresbinary
MD5:932325E4A1B63E2FE9B217DF14412034
SHA256:38A0D0F1495D203A48D368F33C84F33EEE15F9F21F83362695E8D2BB3979F1CE
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
33
DNS requests
23
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.16.164.120:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6544
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4980
EXCEL.EXE
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D
unknown
whitelisted
7436
backgroundTaskHost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
4380
BackgroundTransferHost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
4024
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
4980
EXCEL.EXE
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
4024
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2104
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6032
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2.16.164.120:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
5496
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
2112
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3216
svchost.exe
40.115.3.253:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
20.190.160.4:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.124.78.146
whitelisted
google.com
  • 142.250.186.142
whitelisted
crl.microsoft.com
  • 2.16.164.120
  • 2.16.164.72
whitelisted
client.wns.windows.com
  • 40.115.3.253
whitelisted
login.live.com
  • 20.190.160.4
  • 40.126.32.133
  • 40.126.32.136
  • 20.190.160.132
  • 20.190.160.2
  • 20.190.160.66
  • 20.190.160.131
  • 20.190.160.20
whitelisted
ocsp.digicert.com
  • 184.30.131.245
  • 2.23.77.188
whitelisted
officeclient.microsoft.com
  • 52.109.32.97
whitelisted
ecs.office.com
  • 52.123.128.14
  • 52.123.129.14
whitelisted
roaming.officeapps.live.com
  • 52.109.68.129
whitelisted
arc.msn.com
  • 20.223.35.26
whitelisted

Threats

No threats detected
No debug info