Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
OfficeSetup.exe
|
PE32 executable (GUI) Intel 80386, for MS Windows
|
initial sample
|
||
C:\Users\user\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\6A2A77FA-00BE-4D75-BE01-6F0AFA1F7768
|
XML 1.0 document, ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Office\OTele\officesetup.exe.db
|
SQLite 3.x database, user version 1, last written using SQLite version 3034001, writer version 2, read version 2, file counter
5, database pages 6, cookie 0x3, schema 4, largest root page 6, UTF-8, version-valid-for 5
|
modified
|
||
C:\Users\user\AppData\Local\Microsoft\Office\OTele\officesetup.exe.db-shm
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Office\OTele\officesetup.exe.db-wal
|
SQLite Write-Ahead Log, version 3007000
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\284992-20241025-0629.log
|
Unicode text, UTF-16, little-endian text, with very long lines (2215), with CRLF line terminators
|
dropped
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
52.113.194.132
|
unknown
|
United States
|
||
52.168.117.171
|
unknown
|
United States
|
||
52.109.89.18
|
unknown
|
United States
|
||
52.109.89.117
|
unknown
|
United States
|
||
2.19.126.146
|
unknown
|
European Union
|