Windows Analysis Report
cancellation.one

Overview

General Information

Sample Name: cancellation.one
Analysis ID: 800683
MD5: efae5db57b82eb563d9a5e85d51018b9
SHA1: 2a46f65a5092bff8c5a88d84c78c10336129b6e5
SHA256: 52d47370954612dbb7e9bdb740c8241c999415d62f2846b1c710dbf9e18df09a

Detection

Score: 0
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

No high impact signatures.

Classification

There are no high impact signatures.

Source: C:\Program Files\Microsoft Office\root\Office16\ONENOTE.EXE File read: C:\Program Files\desktop.ini
Source: C:\Program Files\Microsoft Office\root\Office16\ONENOTE.EXE File created: C:\Users\eyup\AppData\Local\Temp\{03CC3D92-E54C-467E-9B0B-62F4355CE739} - OProcSessId.dat
Source: classification engine Classification label: clean0.winONE@1/7@0/22
Source: C:\Program Files\Microsoft Office\root\Office16\ONENOTE.EXE File created: C:\Users\eyup\Documents\{655696E5-AF6E-4A78-A631-7119D5842EE9}
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Program Files\Microsoft Office\root\Office16\ONENOTE.EXE Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Common
Source: C:\Program Files\Microsoft Office\root\Office16\ONENOTE.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\root\Office16\ONENOTE.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\root\Office16\ONENOTE.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\root\Office16\ONENOTE.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\root\Office16\ONENOTE.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\root\Office16\ONENOTE.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\root\Office16\ONENOTE.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\root\Office16\ONENOTE.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\root\Office16\ONENOTE.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\root\Office16\ONENOTE.EXE Process information queried: ProcessInformation
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs