Engine | Download Report | Detection | Info |
---|---|---|---|
|
malicious
Score: 100
|
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
|
IP | Country | Detection |
---|---|---|
162.159.136.232 | United States | |
162.159.130.233 | United States | |
162.159.129.233 | United States | |
Click to see the 3 hidden entries | ||
162.159.128.233 | United States | |
216.38.7.225 | United States | |
162.159.133.233 | United States |
Name | IP | Detection |
---|---|---|
discord.com | 162.159.136.232 | |
cdn.discordapp.com | 162.159.130.233 |
Name | Detection |
---|---|
http://crl.thawte.com/ThawteTimestampingCA.crl0 | |
http://ocsp.thawte.com0 |
Name | File Type | Hashes | Detection |
---|---|---|---|
C:\Users\Public\Natso.bat |
ASCII text, with CRLF, LF line terminators | # | |
C:\Users\user\AppData\Local\Microsoft\Windows\Xbuhnek.exe |
PE32 executable (GUI) Intel 80386, for MS Windows | # | |
C:\Users\Public\cde.bat |
ASCII text, with CRLF line terminators | # | |
Click to see the 5 hidden entries | |||
C:\Users\Public\x.bat |
ASCII text, with CRLF line terminators | # | |
C:\Users\Public\x.vbs |
ASCII text, with CRLF line terminators | # | |
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PEJLKQA8\Xbuhvsl[1] |
ASCII text, with very long lines, with no line terminators | # | |
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PEJLKQA8\Xbuhvsl[2] |
ASCII text, with very long lines, with no line terminators | # | |
C:\Users\user\AppData\Local\hubX.url |
MS Windows 95 Internet shortcut text (URL=<file:\\\C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Xbuhnek.exe>), ASCII text, with CRLF line terminators | # |