Source: global traffic |
TCP traffic: 192.168.2.22:49171 -> 91.235.116.180:80 |
Source: global traffic |
TCP traffic: 91.235.116.180:80 -> 192.168.2.22:49171 |
Source: global traffic |
TCP traffic: 192.168.2.22:49171 -> 91.235.116.180:80 |
Source: global traffic |
TCP traffic: 192.168.2.22:49171 -> 91.235.116.180:80 |
Source: global traffic |
TCP traffic: 91.235.116.180:80 -> 192.168.2.22:49171 |
Source: global traffic |
TCP traffic: 91.235.116.180:80 -> 192.168.2.22:49171 |
Source: global traffic |
TCP traffic: 192.168.2.22:49171 -> 91.235.116.180:80 |
Source: global traffic |
TCP traffic: 91.235.116.180:80 -> 192.168.2.22:49171 |
Source: global traffic |
TCP traffic: 192.168.2.22:49171 -> 91.235.116.180:80 |
Source: global traffic |
TCP traffic: 192.168.2.22:49172 -> 91.235.116.180:80 |
Source: global traffic |
TCP traffic: 91.235.116.180:80 -> 192.168.2.22:49172 |
Source: global traffic |
TCP traffic: 192.168.2.22:49172 -> 91.235.116.180:80 |
Source: global traffic |
TCP traffic: 192.168.2.22:49172 -> 91.235.116.180:80 |
Source: global traffic |
TCP traffic: 91.235.116.180:80 -> 192.168.2.22:49172 |
Source: global traffic |
TCP traffic: 91.235.116.180:80 -> 192.168.2.22:49172 |
Source: global traffic |
TCP traffic: 192.168.2.22:49172 -> 91.235.116.180:80 |
Source: global traffic |
TCP traffic: 91.235.116.180:80 -> 192.168.2.22:49172 |
Source: global traffic |
TCP traffic: 192.168.2.22:49172 -> 91.235.116.180:80 |
Source: global traffic |
TCP traffic: 91.235.116.180:80 -> 192.168.2.22:49172 |
Source: global traffic |
TCP traffic: 192.168.2.22:49172 -> 91.235.116.180:80 |
Source: global traffic |
TCP traffic: 192.168.2.22:49172 -> 91.235.116.180:80 |
Source: global traffic |
TCP traffic: 91.235.116.180:80 -> 192.168.2.22:49172 |
Source: global traffic |
TCP traffic: 192.168.2.22:49173 -> 91.235.116.180:80 |
Source: global traffic |
TCP traffic: 91.235.116.180:80 -> 192.168.2.22:49173 |
Source: global traffic |
TCP traffic: 192.168.2.22:49173 -> 91.235.116.180:80 |
Source: global traffic |
TCP traffic: 192.168.2.22:49173 -> 91.235.116.180:80 |
Source: global traffic |
TCP traffic: 91.235.116.180:80 -> 192.168.2.22:49173 |
Source: global traffic |
TCP traffic: 91.235.116.180:80 -> 192.168.2.22:49173 |
Source: global traffic |
TCP traffic: 192.168.2.22:49173 -> 91.235.116.180:80 |
Source: global traffic |
TCP traffic: 91.235.116.180:80 -> 192.168.2.22:49173 |
Source: global traffic |
TCP traffic: 192.168.2.22:49173 -> 91.235.116.180:80 |
Source: global traffic |
TCP traffic: 192.168.2.22:49173 -> 91.235.116.180:80 |
Source: global traffic |
TCP traffic: 91.235.116.180:80 -> 192.168.2.22:49173 |
Source: global traffic |
TCP traffic: 192.168.2.22:49173 -> 91.235.116.180:80 |
Source: global traffic |
TCP traffic: 192.168.2.22:49173 -> 91.235.116.180:80 |
Source: global traffic |
TCP traffic: 91.235.116.180:80 -> 192.168.2.22:49173 |
Source: global traffic |
TCP traffic: 192.168.2.22:49171 -> 91.235.116.180:80 |
Source: global traffic |
TCP traffic: 192.168.2.22:49174 -> 91.235.116.180:80 |
Source: global traffic |
TCP traffic: 91.235.116.180:80 -> 192.168.2.22:49171 |
Source: global traffic |
TCP traffic: 91.235.116.180:80 -> 192.168.2.22:49174 |
Source: global traffic |
TCP traffic: 192.168.2.22:49174 -> 91.235.116.180:80 |
Source: global traffic |
TCP traffic: 192.168.2.22:49174 -> 91.235.116.180:80 |
Source: global traffic |
TCP traffic: 91.235.116.180:80 -> 192.168.2.22:49174 |
Source: global traffic |
TCP traffic: 91.235.116.180:80 -> 192.168.2.22:49174 |
Source: global traffic |
TCP traffic: 91.235.116.180:80 -> 192.168.2.22:49174 |
Source: global traffic |
TCP traffic: 91.235.116.180:80 -> 192.168.2.22:49174 |
Source: global traffic |
TCP traffic: 192.168.2.22:49174 -> 91.235.116.180:80 |
Source: global traffic |
TCP traffic: 91.235.116.180:80 -> 192.168.2.22:49174 |
Source: global traffic |
TCP traffic: 91.235.116.180:80 -> 192.168.2.22:49174 |
Source: global traffic |
TCP traffic: 91.235.116.180:80 -> 192.168.2.22:49174 |
Source: global traffic |
TCP traffic: 192.168.2.22:49174 -> 91.235.116.180:80 |
Source: global traffic |
TCP traffic: 91.235.116.180:80 -> 192.168.2.22:49174 |
Source: global traffic |
TCP traffic: 91.235.116.180:80 -> 192.168.2.22:49174 |
Source: global traffic |
TCP traffic: 192.168.2.22:49174 -> 91.235.116.180:80 |
Source: global traffic |
TCP traffic: 91.235.116.180:80 -> 192.168.2.22:49174 |
Source: global traffic |
TCP traffic: 91.235.116.180:80 -> 192.168.2.22:49174 |
Source: global traffic |
TCP traffic: 192.168.2.22:49174 -> 91.235.116.180:80 |
Source: global traffic |
TCP traffic: 192.168.2.22:49174 -> 91.235.116.180:80 |
Source: global traffic |
TCP traffic: 192.168.2.22:49174 -> 91.235.116.180:80 |
Source: global traffic |
TCP traffic: 192.168.2.22:49174 -> 91.235.116.180:80 |
Source: global traffic |
TCP traffic: 192.168.2.22:49173 -> 91.235.116.180:80 |
Source: global traffic |
TCP traffic: 192.168.2.22:49174 -> 91.235.116.180:80 |
Source: global traffic |
TCP traffic: 91.235.116.180:80 -> 192.168.2.22:49174 |
Source: global traffic |
TCP traffic: 192.168.2.22:49174 -> 91.235.116.180:80 |
Source: global traffic |
TCP traffic: 192.168.2.22:49174 -> 91.235.116.180:80 |
Source: global traffic |
TCP traffic: 91.235.116.180:80 -> 192.168.2.22:49174 |
Source: global traffic |
TCP traffic: 192.168.2.22:49174 -> 91.235.116.180:80 |
Source: global traffic |
TCP traffic: 192.168.2.22:49175 -> 91.235.116.180:80 |
Source: global traffic |
TCP traffic: 91.235.116.180:80 -> 192.168.2.22:49175 |
Source: global traffic |
TCP traffic: 192.168.2.22:49175 -> 91.235.116.180:80 |
Source: global traffic |
TCP traffic: 192.168.2.22:49175 -> 91.235.116.180:80 |
Source: global traffic |
TCP traffic: 91.235.116.180:80 -> 192.168.2.22:49175 |
Source: global traffic |
TCP traffic: 91.235.116.180:80 -> 192.168.2.22:49175 |
Source: global traffic |
TCP traffic: 192.168.2.22:49175 -> 91.235.116.180:80 |
Source: global traffic |
TCP traffic: 91.235.116.180:80 -> 192.168.2.22:49175 |
Source: global traffic |
TCP traffic: 192.168.2.22:49175 -> 91.235.116.180:80 |
Source: global traffic |
TCP traffic: 192.168.2.22:49173 -> 91.235.116.180:80 |
Source: global traffic |
TCP traffic: 91.235.116.180:80 -> 192.168.2.22:49173 |
Source: global traffic |
TCP traffic: 192.168.2.22:49173 -> 91.235.116.180:80 |
Source: global traffic |
TCP traffic: 192.168.2.22:49173 -> 91.235.116.180:80 |
Source: global traffic |
TCP traffic: 91.235.116.180:80 -> 192.168.2.22:49173 |
Source: global traffic |
TCP traffic: 192.168.2.22:49174 -> 91.235.116.180:80 |
Source: global traffic |
TCP traffic: 91.235.116.180:80 -> 192.168.2.22:49174 |
Source: global traffic |
TCP traffic: 192.168.2.22:49174 -> 91.235.116.180:80 |
Source: global traffic |
TCP traffic: 192.168.2.22:49174 -> 91.235.116.180:80 |
Source: global traffic |
TCP traffic: 91.235.116.180:80 -> 192.168.2.22:49174 |
Source: global traffic |
TCP traffic: 192.168.2.22:49174 -> 91.235.116.180:80 |
Source: global traffic |
TCP traffic: 192.168.2.22:49173 -> 91.235.116.180:80 |
Source: global traffic |
TCP traffic: 192.168.2.22:49174 -> 91.235.116.180:80 |
Source: global traffic |
TCP traffic: 91.235.116.180:80 -> 192.168.2.22:49174 |
Source: global traffic |
TCP traffic: 192.168.2.22:49174 -> 91.235.116.180:80 |
Source: global traffic |
TCP traffic: 91.235.116.180:80 -> 192.168.2.22:49175 |
Source: global traffic |
TCP traffic: 192.168.2.22:49175 -> 91.235.116.180:80 |
Source: global traffic |
TCP traffic: 192.168.2.22:49175 -> 91.235.116.180:80 |
Source: global traffic |
TCP traffic: 91.235.116.180:80 -> 192.168.2.22:49175 |
Source: global traffic |
TCP traffic: 91.235.116.180:80 -> 192.168.2.22:49173 |
Source: global traffic |
TCP traffic: 192.168.2.22:49173 -> 91.235.116.180:80 |
Source: global traffic |
TCP traffic: 192.168.2.22:49173 -> 91.235.116.180:80 |
Source: global traffic |
TCP traffic: 91.235.116.180:80 -> 192.168.2.22:49173 |
Source: global traffic |
TCP traffic: 91.235.116.180:80 -> 192.168.2.22:49174 |
Source: global traffic |
TCP traffic: 192.168.2.22:49174 -> 91.235.116.180:80 |
Source: global traffic |
TCP traffic: 192.168.2.22:49174 -> 91.235.116.180:80 |
Source: ~WRS{FC65F658-05F2-4F35-9C52-226D776E880F}.tmp.0.dr |
String found in binary or memory: http://polpharmar.com/test.html |
Source: ~WRF{9F5FB543-D04B-49F9-BFE7-67526990F982}.tmp.0.dr |
String found in binary or memory: http://polpharmar.com/test.html% |
Source: ~WRF{9F5FB543-D04B-49F9-BFE7-67526990F982}.tmp.0.dr |
String found in binary or memory: http://polpharmar.com/test.html%x-usc:http://polpharmar.com/test.html |
Source: ~WRF{9F5FB543-D04B-49F9-BFE7-67526990F982}.tmp.0.dr |
String found in binary or memory: http://polpharmar.com/test.htmlyX |
Source: document.xml.rels, type: SAMPLE |
Matched rule: SUSP_Doc_WordXMLRels_May22 date = 2022-05-30, author = Tobias Michalski, Christian Burkard, Wojciech Cieslak, description = Detects a suspicious pattern in docx document.xml.rels file as seen in CVE-2022-30190 / Follina exploitation, score = , reference = https://doublepulsar.com/follina-a-microsoft-office-code-execution-vulnerability-1a47fce5629e, modified = 2022-06-20, hash = 62f262d180a5a48f89be19369a8425bec596bc6a02ed23100424930791ae3df0 |
Source: document.xml.rels, type: SAMPLE |
Matched rule: EXPL_CVE_2021_40444_Document_Rels_XML date = 2021-09-10, author = Jeremy Brown / @alteredbytes, description = Detects indicators found in weaponized documents that exploit CVE-2021-40444, reference = https://twitter.com/AlteredBytes/status/1435811407249952772 |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |