Windows Analysis Report
MissingInvoices.xls

Overview

General Information

Sample name: MissingInvoices.xls
Analysis ID: 1541130
MD5: 9756ba64da784ff1e1fa8844c89d72c0
SHA1: d5a0e6dd911e37c9f5c0eeca310e9850fb8f1e0c
SHA256: 6ea5375726cf3ecf59dddf9e3b2a83384158adb17fb9550c67af8e2bddb8330d
Infos:

Detection

Score: 2
Range: 0 - 100
Whitelisted: false
Confidence: 60%

Signatures

Document misses a certain OLE stream usually present in this Microsoft Office document type
Potential document exploit detected (performs HTTP gets)
Potential document exploit detected (unknown TCP traffic)
Sigma detected: Excel Network Connections
Sigma detected: Suspicious Office Outbound Connections

Classification

Source: unknown HTTPS traffic detected: 13.107.253.45:443 -> 192.168.2.17:49723 version: TLS 1.2
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49724 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49724 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49724 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49724 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49724 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49724 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49724 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49724 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49724 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49723 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49723
Source: global traffic TCP traffic: 192.168.2.17:49724 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49724
Source: global traffic TCP traffic: 192.168.2.17:49724 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49724 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49724
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49724
Source: global traffic TCP traffic: 192.168.2.17:49724 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49724
Source: global traffic TCP traffic: 192.168.2.17:49724 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49724
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49724
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49724
Source: global traffic TCP traffic: 192.168.2.17:49724 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49724
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49724
Source: global traffic TCP traffic: 192.168.2.17:49724 -> 13.107.253.45:443
Source: global traffic TCP traffic: 192.168.2.17:49724 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49724
Source: global traffic TCP traffic: 192.168.2.17:49724 -> 13.107.253.45:443
Source: global traffic TCP traffic: 13.107.253.45:443 -> 192.168.2.17:49724
Source: excel.exe Memory has grown: Private usage: 1MB later: 73MB
Source: unknown Network traffic detected: HTTP traffic on port 49724 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49723 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49724
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49723
Source: unknown HTTPS traffic detected: 13.107.253.45:443 -> 192.168.2.17:49723 version: TLS 1.2
Source: MissingInvoices.xls OLE stream indicators for Word, Excel, PowerPoint, and Visio: all false
Source: classification engine Classification label: clean2.winXLS@3/4@0/70
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE File created: C:\Users\user\AppData\Local\Temp\{DD13961B-67FA-4DCB-BACA-B9FF13AE3FF6} - OProcSessId.dat
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE File read: C:\Users\desktop.ini
Source: unknown Process created: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" "C:\Users\user\Desktop\MissingInvoices.xls"
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{77F10CF0-3DB5-4966-B520-B7C54FD35ED6}\InProcServer32
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Common
Source: MissingInvoices.xls Initial sample: OLE indicators vbamacros = False
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exe Thread delayed: delay time: 120000
Source: C:\Windows\splwow64.exe Thread delayed: delay time: 120000
Source: C:\Windows\splwow64.exe Thread delayed: delay time: 120000
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information queried: ProcessInformation
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs