flash

Claim Covid Tvx - Bandoir PBR.docx

Status: finished
Submission Time: 19.05.2021 20:04:07
Clean

Comments

Tags

Details

  • Analysis ID:
    417616
  • API (Web) ID:
    785215
  • Analysis Started:
    19.05.2021 20:11:36
  • Analysis Finished:
    19.05.2021 20:21:46
  • MD5:
    405825f6d97456d98d1620db5d1f8314
  • SHA1:
    74a879ae98debb1449692440266e37738d2a7d72
  • SHA256:
    3d6b6526bbc91680db4b6aac33f809bd1758c37be92c6a5193620011c74bcf5e
  • Technologies:
Full Report Management Report IOC Report Engine Info Verdict Score Reports

System: Windows 7 x64 SP1 with Office 2010 SP2 (IE 11, FF52, Chrome 57, Adobe Reader DC 15, Flash 25.0.0.127, Java 8 Update 121, .NET 4.6.2)

clean
0/100

System: Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
Run Condition: Potential for more IOCs and behavior

clean
0/100

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{1BCB42A3-025D-4403-9DBE-B492A11253DC}.tmp
data
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{3A3DB071-4F03-4D2B-8C5C-F1ADB9722678}.tmp
data
#
C:\Users\user\AppData\Local\Temp\msoCB89.tmp
GIF image data, version 89a, 15 x 15
#
Click to see the 5 hidden entries
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Claim Covid Tvx - Bandoir PBR.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Wed Aug 26 14:08:17 2020, mtime=Wed Aug 26 14:08:17 2020, atime=Thu May 20 02:12:35 2021, length=16919, window=hide
#
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Roaming\Microsoft\Templates\~$Normal.dotm
data
#
C:\Users\user\AppData\Roaming\Microsoft\UProof\ExcludeDictionaryFR040c.lex
Little-endian UTF-16 Unicode text, with no line terminators
#
C:\Users\user\Desktop\~$aim Covid Tvx - Bandoir PBR.docx
data
#