Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 185.199.108.133:443 -> 192.168.2.22:49171 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 185.199.108.133:443 -> 192.168.2.22:49171 |
Source: global traffic | TCP traffic: 185.199.108.133:443 -> 192.168.2.22:49171 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 185.199.108.133:443 -> 192.168.2.22:49171 |
Source: global traffic | TCP traffic: 185.199.108.133:443 -> 192.168.2.22:49171 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 185.199.108.133:443 -> 192.168.2.22:49171 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 185.199.108.133:443 -> 192.168.2.22:49171 |
Source: global traffic | TCP traffic: 185.199.108.133:443 -> 192.168.2.22:49171 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 185.199.108.133:443 -> 192.168.2.22:49171 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 185.199.108.133:443 -> 192.168.2.22:49171 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 185.199.108.133:443 -> 192.168.2.22:49171 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 185.199.108.133:443 -> 192.168.2.22:49171 |
Source: global traffic | TCP traffic: 185.199.108.133:443 -> 192.168.2.22:49171 |
Source: global traffic | TCP traffic: 185.199.108.133:443 -> 192.168.2.22:49171 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 185.199.108.133:443 -> 192.168.2.22:49171 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 185.199.108.133:443 -> 192.168.2.22:49171 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 185.199.108.133:443 -> 192.168.2.22:49171 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 185.199.108.133:443 -> 192.168.2.22:49171 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 185.199.108.133:443 -> 192.168.2.22:49171 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 185.199.108.133:443 -> 192.168.2.22:49171 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 185.199.108.133:443 -> 192.168.2.22:49171 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 185.199.108.133:443 -> 192.168.2.22:49171 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 185.199.108.133:443 -> 192.168.2.22:49171 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 185.199.108.133:443 -> 192.168.2.22:49171 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 185.199.108.133:443 -> 192.168.2.22:49171 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 185.199.108.133:443 -> 192.168.2.22:49171 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 185.199.108.133:443 -> 192.168.2.22:49171 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 185.199.108.133:443 -> 192.168.2.22:49171 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 185.199.108.133:443 -> 192.168.2.22:49171 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 185.199.108.133:443 -> 192.168.2.22:49171 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49172 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 185.199.108.133:443 -> 192.168.2.22:49172 |
Source: global traffic | TCP traffic: 192.168.2.22:49172 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49172 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 185.199.108.133:443 -> 192.168.2.22:49172 |
Source: global traffic | TCP traffic: 185.199.108.133:443 -> 192.168.2.22:49172 |
Source: global traffic | TCP traffic: 192.168.2.22:49172 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49172 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49172 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 185.199.108.133:443 -> 192.168.2.22:49172 |
Source: global traffic | TCP traffic: 185.199.108.133:443 -> 192.168.2.22:49172 |
Source: global traffic | TCP traffic: 192.168.2.22:49172 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 185.199.108.133:443 -> 192.168.2.22:49172 |
Source: global traffic | TCP traffic: 192.168.2.22:49172 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 185.199.108.133:443 -> 192.168.2.22:49172 |
Source: global traffic | TCP traffic: 185.199.108.133:443 -> 192.168.2.22:49172 |
Source: global traffic | TCP traffic: 185.199.108.133:443 -> 192.168.2.22:49172 |
Source: global traffic | TCP traffic: 192.168.2.22:49172 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 185.199.108.133:443 -> 192.168.2.22:49172 |
Source: global traffic | TCP traffic: 192.168.2.22:49172 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 185.199.108.133:443 -> 192.168.2.22:49172 |
Source: global traffic | TCP traffic: 192.168.2.22:49172 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 185.199.108.133:443 -> 192.168.2.22:49172 |
Source: global traffic | TCP traffic: 192.168.2.22:49172 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 185.199.108.133:443 -> 192.168.2.22:49172 |
Source: global traffic | TCP traffic: 192.168.2.22:49172 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 185.199.108.133:443 -> 192.168.2.22:49172 |
Source: global traffic | TCP traffic: 192.168.2.22:49172 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49172 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 185.199.108.133:443 -> 192.168.2.22:49172 |
Source: global traffic | TCP traffic: 185.199.108.133:443 -> 192.168.2.22:49172 |
Source: global traffic | TCP traffic: 192.168.2.22:49172 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49172 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49172 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49172 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49171 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49172 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49172 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49172 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49172 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49172 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49172 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49172 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49172 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49172 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49172 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49172 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49172 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49172 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49172 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49172 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49172 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49172 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49172 -> 185.199.108.133:443 |
Source: global traffic | TCP traffic: 192.168.2.22:49172 -> 185.199.108.133:443 |
Source: document.xml.rels, type: SAMPLE | Matched rule: SUSP_Doc_WordXMLRels_May22 date = 2022-05-30, author = Tobias Michalski, Christian Burkard, Wojciech Cieslak, description = Detects a suspicious pattern in docx document.xml.rels file as seen in CVE-2022-30190 / Follina exploitation, score = , reference = https://doublepulsar.com/follina-a-microsoft-office-code-execution-vulnerability-1a47fce5629e, modified = 2022-06-20, hash = 62f262d180a5a48f89be19369a8425bec596bc6a02ed23100424930791ae3df0 |
Source: document.xml.rels, type: SAMPLE | Matched rule: INDICATOR_OLE_RemoteTemplate author = ditekSHen, description = Detects XML relations where an OLE object is refrencing an external target in dropper OOXML documents |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX |