Suspicious 80% windows Download

FkSA3WUIlyfC

OOXML masquerade, high compression

OOXML archive contains suspicious extensionOffice extension holds no Office package
SHA-256ed1aa8781a44b0768fd4d51850c082887f21249f9db9ff5c901c9d7b97e9388f

Evidence

English function-word token "this" line 8607667
8607667�<�+� WN���*���PK����-d�Xn𭔼��(�����this.pyc}T�oE�Y�N�%)  h�i��U�Z.�D#iv=;�t;���C�m�,�FF�ɩ9P���N��C�kO�d��S�Y��y�������
Adobe brand impersonation text line 41065084
41065084����������Assets/Reveal.png�PNG  ��� IHDR���������\r�f��XiTXtXML:com.adobe.xmp�����<?xpacket begin="" id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="XMP Core 5.5.0"> <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:exif="http://ns.adobe.com/exif/1.0/" xmlns:tiff="http://ns.adobe.com/tiff/1.0/" xmlns:photoshop="http://ns.adobe.com/photoshop/1.0/" xmlns:xmp="http://ns.adobe.com/xap/1.0/" xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/" xmlns:stEvt="http://ns.adobe.com/xap/1.0/sType/ResourceEvent#" exif:PixelXDimension="256" exif:PixelYDimension="256" exif:ColorSpace="1" tiff:ImageWidth="256" tiff:ImageLe
English function-word token "and" line 85161108
85161108E<��o65#_�� a�=�����7���˳�_����� @���� �anD-nb�8&�����/g�؁A4����ɜ�#bN���ђ�J��%��,J2������}��DŽ!�,Q�x��XAu4J�&�!X#��l��OTF���
Percent-encoded content decoded line 108989395
108989395��IEND�B`�PK��qՇ�������������PK-����D�;\������������6���PointCloudWRC/Assets/colorize_light_theme%28new%29.png�PNG  ��� IHDR���0���0���W����� pHYs�� �� ������sRGB�������gAMA���� �a��IDATx혽R�@�/� U�������N-�� �
Encoded content decoded: hex line 113039141
113039141  $.' ",#(7),01444'9=82<.342���C  2!!22222222222222222222222222222222222222222222222222����(�)"�������������� �������}�!1AQa"q2���#B��R��$3br

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.