Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6402 | Sept. 17, 2021, 11:06 a.m. | Sept. 17, 2021, 11:08 a.m. |
-
WINWORD.EXE "C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE" C:\Users\test22\AppData\Local\Temp\diagram-116.doc
2088
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
164.124.101.2 | Active | Moloch |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
file | C:\Users\test22\AppData\Local\Temp\~$agram-116.doc |
parent_process | winword.exe | martian_process | "C:\PROGRA~2\COMMON~1\MICROS~1\DW\DW20.EXE" -x -s 1464 |