Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
attachment(1).eml
|
RFC 822 mail, ASCII text, with CRLF line terminators
|
initial sample
|
||
C:\Users\user\AppData\Local\Microsoft\FORMS\FRMCACHE.DAT
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\FontCache\4\CatalogCacheMetaData.xml
|
XML 1.0 document, ASCII text, with very long lines (2195), with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\FontCache\4\CloudFonts\Avenir Next LT Pro\25381880192.ttf
|
TrueType Font data, 20 tables, 1st "GDEF", 32 names, Macintosh, Copyright \251 2004 - 2017 Monotype GmbH. All rights reserved.Avenir
Next LT ProBoldMonotype Ima
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\FontCache\4\CloudFonts\Avenir Next LT Pro\26301410506.ttf
|
TrueType Font data, 20 tables, 1st "GDEF", 32 names, Macintosh, Copyright \251 2004 - 2017 Monotype GmbH. All rights reserved.Avenir
Next LT ProRegularMonotype
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\53383A83.dat
|
PNG image data, 96 x 96, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\57F62AA8.dat
|
PNG image data, 96 x 96, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\A2642CED.dat
|
JPEG image data, JFIF standard 1.01, resolution (DPI), density 300x300, segment length 16, baseline, precision 8, 177x177,
components 3
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\B6E71A89.dat
|
PNG image data, 40 x 40, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\ED98F447.dat
|
JPEG image data, JFIF standard 1.01, resolution (DPI), density 300x300, segment length 16, baseline, precision 8, 177x177,
components 3
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Office\MSO3072.acl
|
data
|
dropped
|
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
mira-tmc.tm-4.office.com
|
52.123.243.76
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
52.123.243.76
|
mira-tmc.tm-4.office.com
|
United States
|
||
104.208.16.89
|
unknown
|
United States
|
||
184.28.90.27
|
unknown
|
United States
|