Tbconsulting Company Guidelines Employee Handbook.docx
General Information
Score: | 52 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
AI detected landing page (webpage, office document or email)
AI detected suspicious URL
Suspicious office document detected (based on various text indicators)
Connects to many different domains
Detected hidden input values containing email addresses (often used in phishing pages)
HTML page contains hidden javascript code
Stores files to the Windows start menu directory
- System is w10x64_ra
- WINWORD.EXE (PID: 6952 cmdline:
"C:\Program Files (x86)\Microsoft Office\Root\Office16\WINWORD.EXE" /n "C:\Users\user\Desktop\Tbconsulting Company Guidelines Employee Handbook.docx" /o "" MD5: 1A0C2C2E7D9C4BC18E91604E9B0C7678)
- chrome.exe (PID: 5740 cmdline:
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://mstf.mailsupport-netsuites.online/oVtAwgdE#agavin@tbconsulting.com MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2068 --fi eld-trial- handle=198 8,i,140356 2868431397 8814,14330 2729160344 12988,2621 44 --disab le-feature s=Optimiza tionGuideM odelDownlo ading,Opti mizationHi nts,Optimi zationHint sFetching, Optimizati onTargetPr ediction / prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 7744 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= audio.mojo m.AudioSer vice --lan g=en-US -- service-sa ndbox-type =audio --m ojo-platfo rm-channel -handle=40 76 --field -trial-han dle=1988,i ,140356286 8431397881 4,14330272 9160344129 88,262144 --disable- features=O ptimizatio nGuideMode lDownloadi ng,Optimiz ationHints ,Optimizat ionHintsFe tching,Opt imizationT argetPredi ction /pre fetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
⊘No yara matches
⊘No Sigma rule has matched
⊘No Suricata rule has matched
