IOC Report
OfficeSetup.exe

loading gif

Files

File Path
Type
Category
Malicious
OfficeSetup.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
C:\Users\user\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\6A2A77FA-00BE-4D75-BE01-6F0AFA1F7768
XML 1.0 document, ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Microsoft\Office\OTele\officesetup.exe.db
SQLite 3.x database, user version 1, last written using SQLite version 3034001, writer version 2, read version 2, file counter 5, database pages 6, cookie 0x3, schema 4, largest root page 6, UTF-8, version-valid-for 5
modified
C:\Users\user\AppData\Local\Microsoft\Office\OTele\officesetup.exe.db-shm
data
dropped
C:\Users\user\AppData\Local\Microsoft\Office\OTele\officesetup.exe.db-wal
SQLite Write-Ahead Log, version 3007000
dropped
C:\Users\user\AppData\Local\Temp\284992-20241025-0629.log
Unicode text, UTF-16, little-endian text, with very long lines (2215), with CRLF line terminators
dropped

IPs

IP
Domain
Country
Malicious
52.113.194.132
unknown
United States
52.168.117.171
unknown
United States
52.109.89.18
unknown
United States
52.109.89.117
unknown
United States
2.19.126.146
unknown
European Union