Engine | Download Report | Detection | Info |
---|---|---|---|
|
malicious
Score: 100
|
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
|
IP | Country | Detection |
---|---|---|
162.159.138.232 | United States | |
79.134.225.12 | Switzerland | |
162.159.129.233 | United States | |
Click to see the 3 hidden entries | ||
162.159.135.233 | United States | |
162.159.135.232 | United States | |
162.159.134.233 | United States |
Name | IP | Detection |
---|---|---|
asf-ris-prod-neurope.northeurope.cloudapp.azure.com | 168.63.67.155 | |
discord.com | 162.159.135.232 | |
cdn.discordapp.com | 162.159.134.233 |
Name | Detection |
---|---|
http://gorohov.narod.ru/index.htm | |
https://discord.com/newS | |
Http://gorohov.narod.ru | |
Click to see the 1 hidden entries | |
https://discord.com/new |
Name | File Type | Hashes | Detection |
---|---|---|---|
C:\Users\Public\Natso.bat |
ASCII text, with CRLF, LF line terminators | # | |
C:\Users\user\AppData\Local\Qspjsec.exe |
PE32 executable (GUI) Intel 80386, for MS Windows | # | |
C:\Users\Public\cde.bat |
ASCII text, with CRLF line terminators | # | |
Click to see the 6 hidden entries | |||
C:\Users\Public\x.bat |
ASCII text, with CRLF line terminators | # | |
C:\Users\Public\x.vbs |
ASCII text, with CRLF line terminators | # | |
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\QspjKKK[1] |
ASCII text, with very long lines, with no line terminators | # | |
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\QspjKKK[1] |
ASCII text, with very long lines, with no line terminators | # | |
C:\Users\user\AppData\Local\Qspj.url |
MS Windows 95 Internet shortcut text (URL=<file:\\\C:\\Users\\user\\AppData\\Local\\Qspjsec.exe>), ASCII text, with CRLF line terminators | # | |
C:\Users\user\AppData\Roaming\gate\logs.dat |
data | # |