Engine | Download Report | Detection | Info |
---|---|---|---|
|
malicious
Score: 88
|
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
|
IP | Country | Detection |
---|---|---|
20.106.232.4 | United States | |
195.133.18.171 | Russian Federation |
Name | Detection |
---|---|
https://contoso.com/Icon | |
http://crl.microq | |
http://195.133.18.171/ttruugh.txt | |
Click to see the 17 hidden entries | |
http://20.106.232.4 | |
http://20.106.232.4x | |
http://20.106.232.48 | |
http://20.106.232.4/dll/new.pdf | |
http://195.133.18.171x | |
http://20.106.232.4/rumpe/newrumpe.pdf | |
https://contoso.com/License | |
http://www.microsoft.co | |
https://contoso.com/ | |
http://195.133.18.171 | |
https://go.micro | |
http://pesterbdd.com/images/Pester.png | |
https://nuget.org/nuget.exe | |
http://www.apache.org/licenses/LICENSE-2.0.html | |
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name | |
https://github.com/Pester/Pester | |
http://nuget.org/NuGet.exe |
Name | File Type | Hashes | Detection |
---|---|---|---|
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\ModuleAnalysisCache |
data | # | |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive |
data | # | |
C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_aldovbbj.0fp.ps1 |
very short file (no magic) | # | |
Click to see the 10 hidden entries | |||
C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_era3lqvo.5cl.ps1 |
very short file (no magic) | # | |
C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_u0rhufd0.t31.psm1 |
very short file (no magic) | # | |
C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_uh3x3r0z.4n5.psm1 |
very short file (no magic) | # | |
C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_yb2i5nut.0mf.psm1 |
very short file (no magic) | # | |
C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_zpnb2wuj.mn5.ps1 |
very short file (no magic) | # | |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-ms (copy) |
data | # | |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\KCOOD8DGHH3SAH4080U5.temp |
data | # | |
C:\Users\user\Documents\20220514\PowerShell_transcript.035347.PDp+ZyLV.20220514152147.txt |
UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators | # | |
C:\Users\user\Documents\20220514\PowerShell_transcript.035347.yPH19KjK.20220514152144.txt |
UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators | # | |
C:\Users\user\Documents\20220514\PowerShell_transcript.035347.z_SSE0i6.20220514152153.txt |
UTF-8 Unicode (with BOM) text, with CRLF line terminators | # |