Engine | Download Report | Detection | Info |
---|---|---|---|
|
malicious
|
||
|
malicious
Score: 100
|
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
|
IP | Country | Detection |
---|---|---|
35.242.251.130 | United States | |
63.250.39.243 | United States | |
94.136.40.82 | United Kingdom | |
Click to see the 4 hidden entries | ||
185.98.131.147 | France | |
122.114.66.86 | China | |
3.135.49.148 | United States | |
23.20.239.12 | United States |
Name | IP | Detection |
---|---|---|
www.zcs-edu.com | 0.0.0.0 | |
www.axcyl.com | 0.0.0.0 | |
www.brandbank.news | 0.0.0.0 | |
Click to see the 17 hidden entries | ||
www.qadmin.com | 0.0.0.0 | |
www.matbaadukkanim.com | 0.0.0.0 | |
www.vamojunto.com | 0.0.0.0 | |
www.bookwormegy.com | 0.0.0.0 | |
www.kafakoc.com | 0.0.0.0 | |
www.mymtaporta.com | 0.0.0.0 | |
www.samdeng.works | 0.0.0.0 | |
www.bridgejfc.com | 94.136.40.82 | |
www.3dlasermaroc.com | 0.0.0.0 | |
www.usepelican.com | 0.0.0.0 | |
www.shimi783.info | 0.0.0.0 | |
3dlasermaroc.com | 185.98.131.147 | |
www.porcber.com | 63.250.39.243 | |
balancer.wixdns.net | 35.242.251.130 | |
www.yyw518.com | 122.114.66.86 | |
HDRedirect-LB5-1afb6e2973825a56.elb.us-east-1.amazonaws.com | 23.20.239.12 | |
prod-sav-park-lb01-1919960993.us-east-2.elb.amazonaws.com | 3.135.49.148 |
Name | Detection |
---|---|
http://www.bridgejfc.com/mq3/?Kxlpd=usiFhkEA2/xQfSWIf5NGRhfLT8+t9rWHJvPEvA/+NM3yMCY4ViL3D3aLSorWeJjb+qc5&tpeDP4=aN6tXx | |
http://www.porcber.comReferer: | |
http://www.bridgejfc.com/mq3/ | |
Click to see the 89 hidden entries | |
http://www.3dlasermaroc.com/mq3/www.porcber.com | |
http://www.yyw518.com/mq3/ | |
http://www.yyw518.com/mq3/?tpeDP4=aN6tXx&Kxlpd=bMzkr1fzZV+5QtXNWK4LXWvgw9C8VqyMR5lohTVdFC9G3pcizxH8g+YNb0t5pLB/ZO8J | |
http://www.bookwormegy.com/mq3/?tpeDP4=aN6tXx&Kxlpd=jbVBrWG8kPPy1CntJKnIS/p3pTRMEOwQ7pcd0/8muHz8lgjxNZOf5/N47Cv4WKIkQI5C | |
http://www.vamojunto.com/mq3/ | |
http://www.porcber.com/mq3/www.samdeng.works | |
http://www.porcber.com | |
http://www.3dlasermaroc.com/mq3/ | |
http://www.axcyl.com/mq3/ | |
http://www.porcber.com/mq3/ | |
http://www.axcyl.com/mq3/?tpeDP4=aN6tXx&Kxlpd=Ucg4IdL9jFr4XeSjaPMyHB4uwBktJa1xNFlwHiqXLBzLuD0Ne+QKmAu6UBl6f+0aCpLv | |
http://www.vamojunto.com/mq3/?Kxlpd=G5Xu6NHE4SkrvqPWXnU3UeXHC3kT8kLmWInNSoQ44xAbeTfsQH//0ntHgBoI/3bOih10&tpeDP4=aN6tXx | |
http://www.3dlasermaroc.com/mq3/?Kxlpd=YpYaXTMBQs0E5vLJ/Yd9Yn8LoZOIuIOD62g1IdciXa5/abOgLLAXWzIHQlYdUNrQ6hv1&tpeDP4=aN6tXx | |
http://www.brandbank.news | |
http://www.zcs-edu.com/mq3/ | |
http://www.kafakoc.com/mq3/www.shimi783.info | |
http://www.bridgejfc.comReferer: | |
http://www.msn.com/de-ch/?ocid=iehp | |
http://www.matbaadukkanim.com/mq3/www.brandbank.news | |
http://www.carterandcone.coml | |
https://www.hugedomains.com/domain_profile.cfm?d=vamojunto&e=com | |
http://www.qadmin.comReferer: | |
http://www.qadmin.com/mq3/www.vamojunto.com | |
http://www.mymtaporta.comReferer: | |
http://www.vamojunto.com | |
http://www.brandbank.news/mq3/www.axcyl.com | |
http://www.vamojunto.comReferer: | |
http://www.brandbank.news/mq3/ | |
http://www.mymtaporta.com | |
http://www.bridgejfc.com/mq3/www.matbaadukkanim.com | |
http://www.mymtaporta.com/mq3/www.kafakoc.com | |
http://www.apache.org/licenses/LICENSE-2.0 | |
http://www.jiyu-kobo.co.jp/ | |
http://www.zcs-edu.com/mq3/www.usepelican.com | |
http://www.qadmin.com/mq3/ | |
http://www.kafakoc.com/mq3/ | |
http://www.3dlasermaroc.com | |
http://www.kafakoc.comReferer: | |
https://www.hugedomains.com/domain_profile.cfm?d=vamojunto&e=com | |
http://www.usepelican.com/mq3/www.bookwormegy.com | |
http://www.samdeng.worksReferer: | |
http://www.founder.com.cn/cn/bThe | |
http://www.founder.com.cn/cn | |
http://www.usepelican.com/mq3/ | |
http://www.brandbank.newsReferer: | |
http://www.shimi783.infoReferer: | |
http://www.mymtaporta.com/mq3/ | |
http://www.usepelican.com | |
http://www.bookwormegy.com | |
http://www.shimi783.info/mq3/ | |
http://www.axcyl.comReferer: | |
http://fontfabrik.com | |
http://www.zcs-edu.comReferer: | |
http://www.matbaadukkanim.com | |
http://www.goodfont.co.kr | |
http://www.yyw518.com | |
http://www.shimi783.info/mq3/www.qadmin.com | |
http://www.axcyl.com | |
http://www.samdeng.works/mq3/www.yyw518.com | |
http://www.bookwormegy.comReferer: | |
http://www.vamojunto.com/mq3/S | |
http://www.yyw518.comReferer: | |
http://www.bookwormegy.com/mq3/ | |
http://www.founder.com.cn/cn/cThe | |
http://www.typography.netD | |
http://www.sajatypeworks.com | |
https://www.samdeng.works/mq3?Kxlpd=OPoK3Mmn | |
http://www.axcyl.com/mq3/www.3dlasermaroc.com | |
http://www.zcs-edu.com | |
http://www.kafakoc.com | |
http://www.sandoll.co.kr | |
http://www.msn.com/ocid=iehp | |
http://www.matbaadukkanim.comReferer: | |
http://www.matbaadukkanim.com/mq3/ | |
http://www.msn.com/de-ch/ocid=iehp | |
http://www.qadmin.com | |
http://www.sakkal.com | |
http://www.zhongyicts.com.cn | |
http://www.samdeng.works | |
http://www.usepelican.comReferer: | |
http://www.autoitscript.com/autoit3/J | |
http://www.fonts.com | |
http://www.yyw518.com/mq3/www.mymtaporta.com | |
http://www.bookwormegy.com/mq3/www.bridgejfc.com | |
http://www.shimi783.info | |
http://www.samdeng.works/mq3/ | |
http://www.3dlasermaroc.comReferer: | |
http://www.tiro.com | |
http://www.bridgejfc.com |
Name | File Type | Hashes | Detection |
---|---|---|---|
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\Purchase Contract.exe.log |
ASCII text, with CRLF line terminators | # | |
C:\Users\user\AppData\Local\Temp\DB1 |
SQLite 3.x database, last written using SQLite version 3024000 | # | |
C:\Users\user\AppData\Local\Temp\S-zzxp\updategtmlg.exe |
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows | # | |
Click to see the 7 hidden entries | |||
C:\Users\user\AppData\Roaming\72R9-CPB\72Rlogrf.ini |
data | # | |
C:\Users\user\AppData\Roaming\72R9-CPB\72Rlogri.ini |
data | # | |
C:\Users\user\AppData\Roaming\72R9-CPB\72Rlogrv.ini |
data | # | |
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\updategtmlg.exe.log |
ASCII text, with CRLF line terminators | # | |
C:\Users\user\AppData\Roaming\72R9-CPB\72Rlogim.jpeg |
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 1280x1024, frames 3 | # | |
C:\Users\user\AppData\Roaming\72R9-CPB\72Rlogrg.ini |
data | # | |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms |
MS Windows shortcut, Item id list present, Points to a file or directory, Read-Only, Directory, ctime=Wed Apr 11 22:38:20 2018, mtime=Tue Apr 28 09:15:55 2020, atime=Tue Apr 28 09:15:54 2020, length=8192, window=hide | # |