Engine | Download Report | Detection | Info |
---|---|---|---|
|
malicious
Score: 64
|
System: Windows 7 x64 SP1 with Office 2010 SP1 (IE 11, FF52, Chrome 57, Adobe Reader DC 15, Flash 25.0.0.127, Java 8 Update 121, .NET 4.6.2)
|
|
|
malicious
Score: 64
|
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Run Condition: Potential for more IOCs and behavior
|
IP | Country | Detection |
---|---|---|
213.226.114.15 | Russian Federation |
Name | IP | Detection |
---|---|---|
telemetrysystemcollection.com | 213.226.114.15 | |
collectiontelemetrysystem.com | 213.226.114.15 |
Name | Detection |
---|---|
https://telemetrysystemcollection.com/m8YYdu/mCQ2U9/home.aspx | |
http://collectiontelemetrysystem.com/cAUtfkUDaptk/ZRSeiy/requets/index.php | |
https://telemetrysystemcollection.com/m8YYdu/mCQ2U9/auth.aspx | |
Click to see the 3 hidden entries | |
http://telemetrysystemcollection.com/m8YYdu/mCQ2U9/home.aspx | |
https://collectiontelemetrysystem.com/m8YYdu/mCQ2U9/auth.aspx | |
http://collectiontelemetrysystem.com/m8YYdu/mCQ2U9/home.aspx |
Name | File Type | Hashes | Detection |
---|---|---|---|
C:\Users\user\AppData\Local\AdobeFontPack\main.dll |
PE32 executable (DLL) (console) Intel 80386, for MS Windows | # | |
C:\Users\user\AppData\Local\x86\5507.nls |
PE32 executable (DLL) (console) Intel 80386, for MS Windows | # | |
C:\Config.Msi\68bd59.rbs |
data | # | |
Click to see the 9 hidden entries | |||
C:\Users\user\AppData\Local\AdobeFontPack\notify.vbs |
ASCII text, with CRLF line terminators | # | |
C:\Users\user\AppData\Local\Temp\~DF275DF4B13EC3E34F.TMP |
data | # | |
C:\Users\user\AppData\Local\Temp\~DF6CBE8E5B62F6E221.TMP |
data | # | |
C:\Users\user\AppData\Local\Temp\~DF84F6DE3826C4FEB0.TMP |
data | # | |
C:\Windows\Installer\68bd57.msi |
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Adobe Font Pack 3.0.12.9, Author: Adobe Inc., Keywords: Installer, Comments: Adobe Font Pack, Template (…) | # | |
C:\Windows\Installer\68bd58.ipi |
Composite Document File V2 Document, Cannot read section info | # | |
C:\Windows\Installer\68bd5a.msi |
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Adobe Font Pack 3.0.12.9, Author: Adobe Inc., Keywords: Installer, Comments: Adobe Font Pack, Template (…) | # | |
C:\Windows\Installer\MSI7D9A.tmp |
data | # | |
C:\Windows\Installer\SourceHash{CC038BA5-7236-4713-8948-DFF082243638} |
Composite Document File V2 Document, Cannot read section info | # |