Windows Analysis Report
ACH-6573-15March.xlsx

Overview

General Information

Sample name: ACH-6573-15March.xlsx
Analysis ID: 1411152
MD5: fde60a11d2d5ab4723e863053b434337
SHA1: 7afbbc76fde0162904ad9665863a439de8c7a650
SHA256: afacfa9dddc8e1170e6e30352be71bb8d7484ea9ceec0671aa9877805c456420
Infos:

Detection

Score: 52
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Detected suspicious Microsoft Office reference URL
Document Viewer accesses SMB path (likely to steal NTLM hashes or to download payload)
Opens network shares
Potential document exploit detected (performs HTTP gets)
Potential document exploit detected (unknown TCP traffic)
Queries information about the installed CPU (vendor, model number etc)
Sigma detected: Excel Network Connections
Sigma detected: Suspicious Office Outbound Connections

Classification

Exploits

barindex
Source: drawing1.xml.rels Extracted files from sample: file:///\\147.182.156.154\share\excel_document_open.xlsx.vbs...
Source: unknown HTTPS traffic detected: 13.107.213.40:443 -> 192.168.2.17:49718 version: TLS 1.2
Source: unknown HTTPS traffic detected: 13.107.213.40:443 -> 192.168.2.17:49719 version: TLS 1.2
Source: unknown HTTPS traffic detected: 13.107.213.40:443 -> 192.168.2.17:49721 version: TLS 1.2
Source: unknown HTTPS traffic detected: 13.107.213.40:443 -> 192.168.2.17:49720 version: TLS 1.2
Source: unknown HTTPS traffic detected: 13.107.213.40:443 -> 192.168.2.17:49722 version: TLS 1.2
Source: global traffic TCP traffic: 192.168.2.17:49718 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49718 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49719 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49719 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49718 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49720 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49719 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49720 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49720 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49721 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49721 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49721 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49722 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49722 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49722 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49718 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49718 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49718 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49719 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49719 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49719 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49721 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49720 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49722 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49720 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49721 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49722 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49720 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49721 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49722 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49718 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49718 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49718 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49718 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49720 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49720 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49720 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49724 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49724 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49724 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49721 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49721 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49721 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49725 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49725 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49725 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49722 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49722 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49722 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49719 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49719 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49719 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49726 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49726 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49726 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49727 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49727 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49727 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49724 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49724 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49725 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49725 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49726 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49726 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49727 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49727 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49724 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49724 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49724 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49725 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49725 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49725 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49726 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49726 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49726 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49727 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49727 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49727 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49718 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49718
Source: global traffic TCP traffic: 192.168.2.17:49718 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49719 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49719
Source: global traffic TCP traffic: 192.168.2.17:49719 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49718 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49718
Source: global traffic TCP traffic: 192.168.2.17:49720 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49720
Source: global traffic TCP traffic: 192.168.2.17:49719 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49719
Source: global traffic TCP traffic: 192.168.2.17:49720 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49720 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49720
Source: global traffic TCP traffic: 192.168.2.17:49721 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49721
Source: global traffic TCP traffic: 192.168.2.17:49721 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49721 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49721
Source: global traffic TCP traffic: 192.168.2.17:49722 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49722
Source: global traffic TCP traffic: 192.168.2.17:49722 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49722 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49722
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49718
Source: global traffic TCP traffic: 192.168.2.17:49718 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49718 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49718
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49718
Source: global traffic TCP traffic: 192.168.2.17:49718 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49719
Source: global traffic TCP traffic: 192.168.2.17:49719 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49719 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49719
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49719
Source: global traffic TCP traffic: 192.168.2.17:49719 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49721
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49720
Source: global traffic TCP traffic: 192.168.2.17:49721 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49720 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49722
Source: global traffic TCP traffic: 192.168.2.17:49722 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49720 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49720
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49720
Source: global traffic TCP traffic: 192.168.2.17:49721 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49721
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49721
Source: global traffic TCP traffic: 192.168.2.17:49722 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49722
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49722
Source: global traffic TCP traffic: 192.168.2.17:49720 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49721 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49722 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49718
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49719
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49722
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49720
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49721
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49718
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49718
Source: global traffic TCP traffic: 192.168.2.17:49718 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49718
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49718
Source: global traffic TCP traffic: 192.168.2.17:49718 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49718 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49718
Source: global traffic TCP traffic: 192.168.2.17:49718 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49718
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49720
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49720
Source: global traffic TCP traffic: 192.168.2.17:49720 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49720 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49720
Source: global traffic TCP traffic: 192.168.2.17:49720 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49720
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49724 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49724
Source: global traffic TCP traffic: 192.168.2.17:49724 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49724 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49724
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49721
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49721
Source: global traffic TCP traffic: 192.168.2.17:49721 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49721 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49721
Source: global traffic TCP traffic: 192.168.2.17:49721 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49721
Source: global traffic TCP traffic: 192.168.2.17:49725 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49725
Source: global traffic TCP traffic: 192.168.2.17:49725 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49725 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49725
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49722
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49719
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49722
Source: global traffic TCP traffic: 192.168.2.17:49722 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49722 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49722
Source: global traffic TCP traffic: 192.168.2.17:49722 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49722
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49719
Source: global traffic TCP traffic: 192.168.2.17:49719 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49719 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49719
Source: global traffic TCP traffic: 192.168.2.17:49719 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49719
Source: global traffic TCP traffic: 192.168.2.17:49726 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49726
Source: global traffic TCP traffic: 192.168.2.17:49726 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49726 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49726
Source: global traffic TCP traffic: 192.168.2.17:49727 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49727
Source: global traffic TCP traffic: 192.168.2.17:49727 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49727 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49727
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49724
Source: global traffic TCP traffic: 192.168.2.17:49724 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49724
Source: global traffic TCP traffic: 192.168.2.17:49724 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49724
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49725
Source: global traffic TCP traffic: 192.168.2.17:49725 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49725
Source: global traffic TCP traffic: 192.168.2.17:49725 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49725
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49726
Source: global traffic TCP traffic: 192.168.2.17:49726 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49726
Source: global traffic TCP traffic: 192.168.2.17:49726 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49726
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49727
Source: global traffic TCP traffic: 192.168.2.17:49727 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49727
Source: global traffic TCP traffic: 192.168.2.17:49727 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49727
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49724
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49724
Source: global traffic TCP traffic: 192.168.2.17:49724 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49724 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49724
Source: global traffic TCP traffic: 192.168.2.17:49724 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49724
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49725
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49725
Source: global traffic TCP traffic: 192.168.2.17:49725 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49725 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49725
Source: global traffic TCP traffic: 192.168.2.17:49725 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49725
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49726
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49726
Source: global traffic TCP traffic: 192.168.2.17:49726 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49726 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49726
Source: global traffic TCP traffic: 192.168.2.17:49726 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49726
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49727
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49727
Source: global traffic TCP traffic: 192.168.2.17:49727 -> 13.107.213.40:443
Source: global traffic TCP traffic: 192.168.2.17:49727 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49727
Source: global traffic TCP traffic: 192.168.2.17:49727 -> 13.107.213.40:443
Source: global traffic TCP traffic: 13.107.213.40:443 -> 192.168.2.17:49727
Source: excel.exe Memory has grown: Private usage: 1MB later: 103MB
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49722
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49721
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49720
Source: unknown Network traffic detected: HTTP traffic on port 49726 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49727 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49725 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49724 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49721 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49719 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49720 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49722 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49723 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49719
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49718
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49727
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49726
Source: unknown Network traffic detected: HTTP traffic on port 49718 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49725
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49724
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49723
Source: unknown HTTPS traffic detected: 13.107.213.40:443 -> 192.168.2.17:49718 version: TLS 1.2
Source: unknown HTTPS traffic detected: 13.107.213.40:443 -> 192.168.2.17:49719 version: TLS 1.2
Source: unknown HTTPS traffic detected: 13.107.213.40:443 -> 192.168.2.17:49721 version: TLS 1.2
Source: unknown HTTPS traffic detected: 13.107.213.40:443 -> 192.168.2.17:49720 version: TLS 1.2
Source: unknown HTTPS traffic detected: 13.107.213.40:443 -> 192.168.2.17:49722 version: TLS 1.2
Source: classification engine Classification label: mal52.spyw.expl.evad.winXLSX@1/4@0/61
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE File created: C:\Users\user\Desktop\~$ACH-6573-15March.xlsx
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE File created: C:\Users\user\AppData\Local\Temp\{FEB54690-7C4C-4992-964C-DCAE224BF44F} - OProcSessId.dat
Source: ACH-6573-15March.xlsx OLE indicator, Workbook stream: true
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE File read: C:\Users\desktop.ini
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{79eac9d0-baf9-11ce-8c82-00aa004ba90b}\InprocServer32
Source: Window Recorder Window detected: More than 3 window changes detected
Source: ACH-6573-15March.xlsx Initial sample: OLE zip file path = xl/media/image1.gif
Source: ACH-6573-15March.xlsx Initial sample: OLE zip file path = xl/media/image2.png
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Common
Source: ACH-6573-15March.xlsx Initial sample: OLE indicators vbamacros = False
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information queried: ProcessInformation
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Registry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Registry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0

Stealing of Sensitive Information

barindex
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE File opened: \\147.182.156.154\share\EXCEL_DOCUMENT_OPEN.XLSX.vbs
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE File opened: \\147.182.156.154\share\EXCEL_DOCUMENT_OPEN.XLSX.vbs
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE File opened: \\147.182.156.154\share\EXCEL_DOCUMENT_OPEN.XLSX.vbs
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE File opened: \\147.182.156.154\share\EXCEL_DOCUMENT_OPEN.XLSX.vbs
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE File opened: \\147.182.156.154\share\EXCEL_DOCUMENT_OPEN.XLSX.vbs
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE File opened: \\147.182.156.154\share\EXCEL_DOCUMENT_OPEN.XLSX.vbs
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs