Engine | Download Report | Detection | Info |
---|---|---|---|
![]() |
malicious
|
||
![]() |
malicious
Score: 76
|
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
|
|
![]() |
malicious
Score: 100
|
System: Windows 7 x64 SP1 with Office 2010 SP1 (IE 11, FF52, Chrome 57, Adobe Reader DC 15, Flash 25.0.0.127, Java 8 Update 121, .NET 4.6.2)
Run Condition: Potential for more IOCs and behavior
|
IP | Country | Detection |
---|---|---|
185.252.179.165 | Germany | ![]() |
171.22.30.147 | Germany | ![]() |
Name | Detection |
---|---|
http://185.252.179.165/Desktop/dwmfs.exetC: | ![]() |
http://kbfvzoboss.bid/alien/fre.php | ![]() |
http://185.252.179.165/Desktop/dwmfs.exej | ![]() |
Click to see the 11 hidden entries | |
http://alphastand.top/alien/fre.php | ![]() |
http://185.252.179.165/Desktop/dwmfs.exeC: | ![]() |
http://185.252.179.165/Desktop/dwmfs.exe$ | ![]() |
http://185.252.179.165/Desktop/dwmfs.exe | ![]() |
http://alphastand.win/alien/fre.php | ![]() |
http://alphastand.trade/alien/fre.php | ![]() |
http://171.22.30.147/mous/five/fre.php | ![]() |
http://185.252.179.165/Desktop/dwmfs.exejjC: | ![]() |
http://www.ibsensoftware.com/ | ![]() |
http://185.252.179.165/Desktop/dwmfs.exeU | ![]() |
http://185.252.179.165/Desktop/dwmfs.exeT | ![]() |
Name | File Type | Hashes | Detection |
---|---|---|---|
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\dwmfs[1].exe |
PE32 executable (GUI) Intel 80386, for MS Windows | # | ![]() |
C:\Users\user\AppData\Local\Temp\IBM_Centosie.exe |
PE32 executable (GUI) Intel 80386, for MS Windows | # | ![]() |
C:\Users\user\AppData\Roaming\CF97F5\5879F5.exe (copy) |
PE32 executable (GUI) Intel 80386, for MS Windows | # | ![]() |