Engine | Download Report | Detection | Info |
---|---|---|---|
|
malicious
Score: 48
|
System: unknown
|
|
|
malicious
Score: 48
|
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Run Condition: Potential for more IOCs and behavior
|
Name | File Type | Hashes | Detection |
---|---|---|---|
\test.157.245.33.145.nip.io\share\~$covid.docx |
data | # | |
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{B5F5167F-F271-46D7-8AEB-75983AFD1311}.tmp |
data | # | |
C:\Users\user\Desktop\~$vid19-Business-Continuity-Plan.docx |
data | # | |
Click to see the 18 hidden entries | |||
C:\Users\user\AppData\Roaming\Microsoft\UProof\ExcludeDictionaryEN0809.lex |
Little-endian UTF-16 Unicode text, with no line terminators | # | |
C:\Users\user\AppData\Roaming\Microsoft\Templates\~$Normal.dotm |
data | # | |
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat |
ASCII text, with CRLF line terminators | # | |
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\covid.LNK |
MS Windows shortcut, Points to a file or directory, Archive, Normal, ctime=Sun May 31 10:38:05 2020, mtime=Sun May 31 10:43:01 2020, atime=Sun May 31 10:38:05 2020, length=268369, window=hide | # | |
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Covid19-Business-Continuity-Plan.LNK |
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Tue Jan 28 13:45:45 2020, mtime=Tue Jan 28 13:45:45 2020, atime=Sun May 31 15:26:11 2020, length=11737, window=hide | # | |
C:\Users\user\AppData\Local\Temp\{B612B0B2-B525-4994-BA13-69AA466EC808} |
data | # | |
C:\Users\user\AppData\Local\Temp\{772FB100-8698-4036-9A2D-53FC83C46847} |
data | # | |
C:\Users\user\AppData\Local\Temp\msoE666.tmp |
GIF image data, version 89a, 15 x 15 | # | |
C:\Users\user\AppData\Local\Microsoft\Office\14.0\OfficeFileCache\FSD-CNRY.FSD |
data | # | |
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{AA76D942-706C-4B9C-B7BD-8DD71CD1DA9D}.tmp |
data | # | |
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{5E8239B3-643E-4121-B787-B2B1E1B12791}.tmp |
data | # | |
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\C2F5F77F.docx |
Microsoft Word 2007+ | # | |
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\12812B74.jpg |
[TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop Elements 9.0 Windows, datetime=2011:12:29 12:01:20], baseline, precision 8, 2478x414, frames 3 | # | |
C:\Users\user\AppData\Local\Microsoft\Office\14.0\OfficeFileCache\LocalCacheFileEditManager\FSF-{0E1EEE64-E8C6-4E2A-9759-63CF07FD8988}.FSF |
data | # | |
C:\Users\user\AppData\Local\Microsoft\Office\14.0\OfficeFileCache\LocalCacheFileEditManager\FSD-{F7D8C65F-572C-4FF5-9F45-7934BFDD2091}.FSD |
data | # | |
C:\Users\user\AppData\Local\Microsoft\Office\14.0\OfficeFileCache\LocalCacheFileEditManager\FSD-CNRY.FSD |
data | # | |
C:\Users\user\AppData\Local\Microsoft\Office\14.0\OfficeFileCache\FSF-CTBL.FSF |
data | # | |
C:\Users\user\AppData\Local\Microsoft\Office\14.0\OfficeFileCache\FSD-{8154DC8D-D2C2-4459-BE16-62105E44F7E9}.FSD |
data | # |