Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
2021_0002565_DDT.xls
|
Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1252, Create Time/Date: Mon Oct
11 09:03:47 2021, Last Saved Time/Date: Mon Oct 11 09:03:49 2021, Security: 0, Comments: ''BRT
|
initial sample
|
||
C:\Users\alfredo\AppData\Local\Microsoft\FontCache\4\Catalog\ListAll.Json
|
UTF-8 Unicode text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Microsoft\FontCache\4\PreviewFont\flat_officeFontsPreview_4_17.ttf
|
TrueType Font data, 10 tables, 1st "OS/2", 7 names, Microsoft, language 0x409, \251 2018 Microsoft Corporation. All Rights
Reserved.msofp_4_17RegularVersion 4.17;O365
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\D01F1074-7A8E-4E0B-A1C2-7BFA61CB3A1A
|
XML 1.0 document, UTF-8 Unicode text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules.xml
|
XML 1.0 document, ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Microsoft\TokenBroker\Cache\089d66ba04a8cec4bdc5267f42f39cf84278bb67.tbres
|
data
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Microsoft\TokenBroker\Cache\9aad439831564ef9f88438a70a63c87e26ef3852.tbres
|
data
|
dropped
|
||
C:\Users\alfredo\AppData\Roaming\Microsoft\Office\Recent\2021_0002565_DDT.LNK
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Tue Jun 8 14:37:17
2021, mtime=Wed Oct 13 23:49:32 2021, atime=Wed Oct 13 23:49:26 2021, length=51712, window=hide
|
dropped
|
||
C:\Users\alfredo\AppData\Roaming\Microsoft\Office\Recent\index.dat
|
ASCII text, with CRLF line terminators
|
dropped
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
52.113.194.132
|
unknown
|
United States
|
||
52.109.88.177
|
unknown
|
United States
|
||
192.168.2.1
|
unknown
|
unknown
|
||
52.109.28.63
|
unknown
|
United States
|
||
2.21.140.114
|
unknown
|
European Union
|
||
20.50.201.195
|
unknown
|
United States
|
||
52.109.88.34
|
unknown
|
United States
|