Engine | Download Report | Detection | Info |
---|---|---|---|
|
malicious
|
||
|
malicious
Score: 72
|
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
|
|
|
malicious
Score: 72
|
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Run Condition: Run with higher sleep bypass
|
Name | Detection |
---|---|
https://api.ipify.org/ | |
https://ip4.seeip.org/ | |
https://api.ipify.org/https://ip4.seeip.org/runasMicrosoft |
Name | File Type | Hashes | Detection |
---|---|---|---|
C:\ProgramData\jdbv\mewbqt.exe |
PE32 executable (GUI) Intel 80386, for MS Windows | # | |
C:\ProgramData\jdbv\mewbqt.exe:Zone.Identifier |
ASCII text, with CRLF line terminators | # | |
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_SecuriteInfo.com_6c6c96553be7758c65d67e1996229a1974855c0_65bc477d_1b270acd\Report.wer |
Little-endian UTF-16 Unicode text, with CRLF line terminators | # | |
Click to see the 8 hidden entries | |||
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_mewbqt.exe_c7e2feb74c2ebb8cf3759f98d0aa3d959a5e48_69c39734_1bbb3577\Report.wer |
Little-endian UTF-16 Unicode text, with CRLF line terminators | # | |
C:\ProgramData\Microsoft\Windows\WER\Temp\WER1C4.tmp.dmp |
Mini DuMP crash report, 14 streams, Sat Aug 1 07:35:58 2020, 0x1205a4 type | # | |
C:\ProgramData\Microsoft\Windows\WER\Temp\WER2395.tmp.dmp |
Mini DuMP crash report, 14 streams, Sat Aug 1 07:36:07 2020, 0x1205a4 type | # | |
C:\ProgramData\Microsoft\Windows\WER\Temp\WER29FE.tmp.WERInternalMetadata.xml |
XML 1.0 document, Little-endian UTF-16 Unicode text, with CRLF line terminators | # | |
C:\ProgramData\Microsoft\Windows\WER\Temp\WER2EA3.tmp.xml |
XML 1.0 document, ASCII text, with CRLF line terminators | # | |
C:\ProgramData\Microsoft\Windows\WER\Temp\WER679.tmp.WERInternalMetadata.xml |
XML 1.0 document, Little-endian UTF-16 Unicode text, with CRLF line terminators | # | |
C:\ProgramData\Microsoft\Windows\WER\Temp\WER810.tmp.xml |
XML 1.0 document, ASCII text, with CRLF line terminators | # | |
C:\Windows\Tasks\mewbqt.job |
data | # |