Suspicious Wordpad Outbound Connections
Description
Detects a network connection initiated by "wordpad.exe" over uncommon destination ports. This might indicate potential process injection activity from a beacon or similar mechanisms.
Query · sigma
selection: Initiated: 'true' Image|endswith: \wordpad.exe filter_main_ports: DestinationPort: - 80 - 139 - 443 - 445 - 465 - 587 - 993 - 995 condition: selection and not 1 of filter_main_*
Known false positives
- Other ports can be used, apply additional filters accordingly