Skip to content

The Phish Tank - 3a

Category: Snowpoint

Description

The suspicious IP address sent another email, which contained a Microsoft Word document attachment. The user who attempted to open this document saw the banner warning that the document contained macros and immediately closed the document and reported it to Snowpoint’s security team.

The Snowpoint team would like your assistance extracting this Microsoft Word document and analyzing the macros it contains. Based on initial analysis, they believe it is an msfvenom created macro that attempts to make reverse TCP connection back to another computer. Since this is an internal network, they are confident the IP address starts with 10.140.

What IP address does this macro attempt to connect to?

Flag format: IP Address. Example: 10.140.1.1**

Write-up

Flag: 10.140.1.15