Engine | Download Report | Detection | Info |
---|---|---|---|
|
clean
Score: 0
|
System: unknown
|
|
|
clean
Score: 1
|
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Run Condition: Potential for more IOCs and behavior
|
Name | File Type | Hashes | Detection |
---|---|---|---|
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\A6274AEE.wmf |
Targa image data - Map - RLE 65536 x 65536 x 0 "\004" | # | |
C:\Users\user\Desktop\~$rformance Appraisal - Annual.docx |
data | # | |
C:\Users\user\AppData\Roaming\Microsoft\Templates\~$Normal.dotm |
data | # | |
Click to see the 24 hidden entries | |||
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat |
ASCII text, with CRLF line terminators | # | |
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Performance Appraisal - Annual.LNK |
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Thu May 23 20:36:40 2019, mtime=Thu Dec 12 05:26:28 2019, atime=Thu Dec 12 05:26:23 2019, length=120552, window=hide | # | |
C:\Users\user\AppData\Local\Temp\msoE58B.tmp |
GIF image data, version 89a, 15 x 15 | # | |
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.Word\~WRS{44462C4F-69CB-4E7B-9735-780AB5D91A05}.tmp |
data | # | |
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.Word\~WRS{07B48588-0528-415F-B6D3-8DCF84FD13DA}.tmp |
data | # | |
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\EF50DEA7.jpeg |
JPEG image data, JFIF standard 1.01, resolution (DPI), density 200x200, segment length 16, baseline, precision 8, 1548x227, frames 3 | # | |
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\D68FE9E0.wmf |
Targa image data - Map - RLE 65536 x 65536 x 0 "\004" | # | |
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\CCBED945.wmf |
Targa image data - Map - RLE 65536 x 65536 x 0 "\004" | # | |
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\C208664D.wmf |
Targa image data - Map - RLE 65536 x 65536 x 0 "\004" | # | |
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\BD0C9154.wmf |
Targa image data - Map - RLE 65536 x 65536 x 0 "\004" | # | |
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\A7FF8682.wmf |
Targa image data - Map - RLE 65536 x 65536 x 0 "\004" | # | |
C:\Users\user\AppData\Local\Microsoft\Office\OTele\winword.exe.db-wal |
SQLite Write-Ahead Log, version 3007000 | # | |
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\A2B3C6D6.wmf |
Targa image data - Map - RLE 65536 x 65536 x 0 "\004" | # | |
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\7A43A09B.wmf |
Targa image data - Map - RLE 65536 x 65536 x 0 "\004" | # | |
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\6917A217.wmf |
Targa image data - Map - RLE 65536 x 65536 x 0 "\004" | # | |
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\68409AE3.wmf |
Targa image data - Map - RLE 65536 x 65536 x 0 "\004" | # | |
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\511139E9.wmf |
Targa image data - Map - RLE 65536 x 65536 x 0 "\004" | # | |
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\4F405CDF.wmf |
Targa image data - Map - RLE 65536 x 65536 x 0 "\004" | # | |
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\30B4DFEA.wmf |
Targa image data - Map - RLE 65536 x 65536 x 0 "\004" | # | |
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\29294F88.wmf |
Targa image data - Map - RLE 65536 x 65536 x 0 "\004" | # | |
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\1E20D87C.wmf |
Targa image data - Map - RLE 65536 x 65536 x 0 "\004" | # | |
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\135E2061.wmf |
Targa image data - Map - RLE 65536 x 65536 x 0 "\004" | # | |
C:\Users\user\AppData\Local\Microsoft\Office\OTele\winword.exe.db.session-journal |
data | # | |
C:\Users\user\AppData\Local\Microsoft\Office\OTele\winword.exe.db.session |
SQLite 3.x database, last written using SQLite version 3019003 | # |