Engine | Download Report | Detection | Info |
---|---|---|---|
|
malicious
|
||
|
malicious
Score: 100
|
System: unknown
|
IP | Country | Detection |
---|---|---|
195.123.246.12 | Bulgaria |
Name | IP | Detection |
---|---|---|
microsoft-hub-us.com | 195.123.246.12 |
Name | Detection |
---|---|
http://schemas.openformatrg/package/2006/content-t | |
http://cps.root-x1.letsencrypt.org0 | |
http://dublincore.org/schemas/xmls/qdc/2003/04/02/dcterms.xsdom | |
Click to see the 16 hidden entries | |
http://crl.entrust.net/2048ca.crl0 | |
http://schemas.open | |
https://secure.comodo.com/CPS0 | |
http://ocsp.entrust.net0D | |
http://www.diginotar.nl/cps/pkioverheid0 | |
http://crl.pkioverheid.nl/DomOrganisatieLatestCRL-G2.crl0 | |
http://ocsp.int-x3.letsencrypt.org0/ | |
http://dublincore.org/schemas/xmls/qdc/2003/04/02/dc.xsdes | |
http://cert.int-x3.letsencrypt.org/0 | |
http://ocsp.entrust.net03 | |
http://cps.letsencrypt.org0 | |
http://crl.entrust.net/server1.crl0 | |
https://microsoft-hub-us.com/vist | |
http://schemas.openformatrg/package/2006/r | |
https://microsoft-hub-us.com/vist%dContent-Length: | |
http://crl.pkioverheid.nl/DomOvLatestCRL.crl0 |
Name | File Type | Hashes | Detection |
---|---|---|---|
C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\scheduler_a.dll |
PE32 executable (DLL) (console) Intel 80386, for MS Windows | # | |
C:\Users\user\Desktop\~$a.doc |
data | # | |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E0F5C59F9FA661F6F4C50B87FEF3A15A |
data | # | |
Click to see the 13 hidden entries | |||
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E0F5C59F9FA661F6F4C50B87FEF3A15A |
data | # | |
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\AEFAA474.emf |
Windows Enhanced Metafile (EMF) image data version 0x10000 | # | |
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{275A6E0F-5609-4D57-84E2-463105F0A7E3}.tmp |
data | # | |
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{DE42AC8E-14E5-416A-BAD6-76B8126F0853}.tmp |
data | # | |
C:\Users\user\AppData\Local\Temp\VBE\MSForms.exd |
data | # | |
C:\Users\user\AppData\Local\Temp\oleObject1.bin |
Composite Document File V2 Document, Cannot read section info | # | |
C:\Users\user\AppData\Local\Temp\~$demem.docx.zip |
data | # | |
C:\Users\user\AppData\Local\Temp\~$idemem.docx |
data | # | |
C:\Users\user\AppData\Local\Temp\~WRD0000.tmp |
data | # | |
C:\Users\user\AppData\Local\Temp\~WRD0001.tmp |
data | # | |
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\a.LNK |
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Sun Sep 24 13:01:37 2017, mtime=Sun Sep 24 13:01:37 2017, atime=Fri Nov 8 12:08:56 2019, length=776192, window=hide | # | |
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat |
ASCII text, with CRLF line terminators | # | |
C:\Users\user\AppData\Roaming\Microsoft\Templates\~$Normal.dotm |
data | # |