We assess with high confidence that the primary source of infection was a drive-by download. The user visited a website offering the Microsoft Office 2019 Professional Plus installer, along with an activator program named "Office 2013-2019 C2R Install".
The initial malicious file contained an AutoIT script that, upon execution and decryption, drops the OInstall.exe (Office 2013-2019 C2R Install) (MD5: b326fc82fb91811c223965d0d63c7a42) and install.exe (MD5: 6037361243f8c390326debbea5b85ac2) file under the %TEMP% folder, which is a .NET binary that we will be analyzing in this article.
Office 2013-2019 Install is an online installer for Microsoft Office 2019, Microsoft Office 2016, or Microsoft Office 2013 on your PC. The advantage of the program is the ability to install individual Office 2016 components, as well as choose the language of the installed Office suite. Office 2013-2019 Install C2R will automatically download and install any component of MS Office 2013/2016/2019 (x86 / x64) with Selectable Languages. And then, with just one click, it will be activated for FREE.
With the 2013-2019 C2R Office Installer software, you will feel satisfied with its utility, which helps bring complete time-saving and easy installation for first-time users. If you previously installed Microsoft Office to find versions on forums or blogs, now just download this little utility tool, shopping to install Microsoft Office versions is easy. Alternatively, the software can also be used to uninstall Office, providing a solution to the problem of not reinstalling due to the Offcie installation error.
This program designed for on-line installation and activation Microsoft Office 2013/2019 C2R. You also can create custom installation of Office off-line for using later. Also Office 2013-2019 C2R Install allows you to select/install the desired application as opposed to C2R original Office installer and activate it.
Possible solutions
1. Check if your office 2021 installed is pro plus.(it is conflict with different version installed to what are you activating).
2. Check volume edition or retail version or simply convert it.
3. Use KMS MATRIX activator.