IOC Report
https://magentacloud.de/s/2bMe7TmEWH89MxG

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\Downloads\Jahresbericht STaR 2024.zip (copy)
Zip archive data, at least v2.0 to extract, compression method=store
dropped
malicious
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\LOG
ASCII text
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\LOG.old (copy)
ASCII text
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
ASCII text
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
ASCII text
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\0f3a824d-4b83-49e5-a15a-33b04ec83496.tmp
JSON data
modified
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
JSON data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG
ASCII text
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
ASCII text
dropped
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Certificate, Version=3
dropped
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Microsoft Cabinet archive data, Windows 2000/XP setup, 71954 bytes, 1 file, at 0x2c +A "authroot.stl", number 1, 6 datablocks, 0x1 compression
dropped
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
data
dropped
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
data
dropped
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\AdobeCMapFnt23.lst (copy)
PostScript document text
dropped
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\AdobeFnt23.lst.5600
PostScript document text
dropped
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\AdobeSysFnt23.lst (copy)
PostScript document text
dropped
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\Cache\AcroFnt23.lst (copy)
PostScript document text
dropped
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\Cache\AdobeFnt23.lst.5600
PostScript document text
dropped
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
JSON data
dropped
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
JSON data
dropped
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
JSON data
dropped
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
JSON data
dropped
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
JSON data
dropped
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
JSON data
dropped
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
JSON data
dropped
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
JSON data
dropped
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
JSON data
dropped
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
JSON data
dropped
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Banner
JSON data
dropped
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
JSON data
dropped
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
JSON data
dropped
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
JSON data
dropped
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
JSON data
dropped
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\Edit_InApp_Aug2020
JSON data
dropped
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\TESTING
data
dropped
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\SOPHIA.json
JSON data
dropped
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SharedDataEvents
SQLite 3.x database, last written using SQLite version 3040000, file counter 25, database pages 3, cookie 0x2, schema 4, UTF-8, version-valid-for 25
dropped
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SharedDataEvents-journal
SQLite Rollback Journal
dropped
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\UserCache64.bin
data
dropped
C:\Users\user\AppData\Local\Temp\MSI95ebb.LOG
Unicode text, UTF-16, little-endian text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2025-01-16 07-15-59-971.log
ASCII text, with very long lines (393)
dropped
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
ASCII text, with very long lines (393), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\acrobat_sbx\acroNGLLog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\acrocef_low\1c1f3e00-ce3b-4b24-9e60-1b3c1559356a.tmp
gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 42290
dropped
C:\Users\user\AppData\Local\Temp\acrocef_low\4823d41b-a8a5-4bfb-9ff0-ec05c215adf0.tmp
gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 1311022
dropped
C:\Users\user\AppData\Local\Temp\acrocef_low\bdb284c2-a817-4060-adaa-b96861122e39.tmp
gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 299538
dropped
C:\Users\user\AppData\Local\Temp\acrocef_low\cd236f46-f305-44cd-a246-884e53a8a26f.tmp
gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 5111142
dropped
C:\Users\user\AppData\Local\Temp\j43hmrmm.3cx\Jahresbericht STaR 2024\Jahresbericht_STaR_2024.pdf
PDF document, version 1.7, 14 pages
dropped
C:\Users\user\AppData\Local\Temp\unarchiver.log
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Jan 16 11:15:20 2025, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Jan 16 11:15:19 2025, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 5 07:00:51 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Jan 16 11:15:19 2025, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Jan 16 11:15:20 2025, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Jan 16 11:15:19 2025, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\Downloads\Jahresbericht STaR 2024.zip.crdownload
Zip archive data, at least v2.0 to extract, compression method=store
dropped
C:\Users\user\Downloads\d3351d08-a7d6-413e-bd9d-1de38f99d3d9.tmp
Zip archive data, at least v2.0 to extract, compression method=store
dropped
Chrome Cache Entry: 217
ASCII text
dropped
Chrome Cache Entry: 218
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 1920x1080, components 3
downloaded
Chrome Cache Entry: 219
ASCII text
downloaded
Chrome Cache Entry: 220
ASCII text
downloaded
Chrome Cache Entry: 221
ASCII text
dropped
Chrome Cache Entry: 222
ASCII text
downloaded
Chrome Cache Entry: 223
ASCII text
dropped
Chrome Cache Entry: 224
ASCII text, with very long lines (415)
downloaded
Chrome Cache Entry: 225
Unicode text, UTF-8 text
downloaded
Chrome Cache Entry: 226
ASCII text
downloaded
Chrome Cache Entry: 227
ASCII text
dropped
Chrome Cache Entry: 228
ASCII text, with very long lines (23584)
downloaded
Chrome Cache Entry: 229
Unicode text, UTF-8 text, with very long lines (65435)
dropped
Chrome Cache Entry: 230
ASCII text
downloaded
Chrome Cache Entry: 231
ASCII text, with very long lines (788)
dropped
Chrome Cache Entry: 232
ASCII text, with very long lines (10457)
downloaded
Chrome Cache Entry: 233
ASCII text, with very long lines (3930)
downloaded
Chrome Cache Entry: 234
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 235
Unicode text, UTF-8 text, with very long lines (65429)
dropped
Chrome Cache Entry: 236
Zip archive data, at least v2.0 to extract, compression method=store
downloaded
Chrome Cache Entry: 237
Unicode text, UTF-8 text
downloaded
Chrome Cache Entry: 238
Unicode text, UTF-8 text
dropped
Chrome Cache Entry: 239
ASCII text
downloaded
Chrome Cache Entry: 240
Unicode text, UTF-8 text, with very long lines (65460)
dropped
Chrome Cache Entry: 241
ASCII text, with very long lines (47219), with CRLF line terminators
downloaded
Chrome Cache Entry: 242
ASCII text, with very long lines (10457)
dropped
Chrome Cache Entry: 243
ASCII text, with very long lines (12211)
downloaded
Chrome Cache Entry: 244
JSON data
downloaded
Chrome Cache Entry: 245
ASCII text, with very long lines (23584)
dropped
Chrome Cache Entry: 246
ASCII text, with very long lines (65467), with escape sequences
dropped
Chrome Cache Entry: 247
Unicode text, UTF-8 text
downloaded
Chrome Cache Entry: 248
HTML document, ASCII text, with very long lines (451)
dropped
Chrome Cache Entry: 249
ASCII text
dropped
Chrome Cache Entry: 250
ASCII text
dropped
Chrome Cache Entry: 251
Unicode text, UTF-8 text, with very long lines (65459)
dropped
Chrome Cache Entry: 252
ASCII text
dropped
Chrome Cache Entry: 253
Unicode text, UTF-8 text
downloaded
Chrome Cache Entry: 254
ASCII text
downloaded
Chrome Cache Entry: 255
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 256
Unicode text, UTF-8 text
dropped
Chrome Cache Entry: 257
ASCII text, with very long lines (65467), with escape sequences
downloaded
Chrome Cache Entry: 258
ASCII text
downloaded
Chrome Cache Entry: 259
ASCII text, with very long lines (2628)
downloaded
Chrome Cache Entry: 260
ASCII text
downloaded
Chrome Cache Entry: 261
CSV text
downloaded
Chrome Cache Entry: 262
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 1920x1080, components 3
dropped
Chrome Cache Entry: 263
Unicode text, UTF-8 text, with very long lines (56828)
dropped
Chrome Cache Entry: 264
ASCII text, with very long lines (47219), with CRLF line terminators
dropped
Chrome Cache Entry: 265
ASCII text
dropped
Chrome Cache Entry: 266
Web Open Font Format, TrueType, length 67164, version 0.0
downloaded
Chrome Cache Entry: 267
ASCII text, with very long lines (307)
dropped
Chrome Cache Entry: 268
Unicode text, UTF-8 text
dropped
Chrome Cache Entry: 269
Unicode text, UTF-8 text, with very long lines (65459)
dropped
Chrome Cache Entry: 270
Unicode text, UTF-8 text
dropped
Chrome Cache Entry: 271
ASCII text
downloaded
Chrome Cache Entry: 272
ASCII text
downloaded
Chrome Cache Entry: 273
CSV text
dropped
Chrome Cache Entry: 274
ASCII text, with very long lines (788)
downloaded
Chrome Cache Entry: 275
Unicode text, UTF-8 text
dropped
Chrome Cache Entry: 276
ASCII text
dropped
Chrome Cache Entry: 277
ASCII text, with very long lines (32553)
downloaded
Chrome Cache Entry: 278
ASCII text
dropped
Chrome Cache Entry: 279
ASCII text
downloaded
Chrome Cache Entry: 280
ASCII text
downloaded
Chrome Cache Entry: 281
ASCII text
downloaded
Chrome Cache Entry: 282
Unicode text, UTF-8 text, with very long lines (65460)
downloaded
Chrome Cache Entry: 283
ASCII text, with very long lines (65460)
dropped
Chrome Cache Entry: 284
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 285
HTML document, ASCII text, with very long lines (451)
downloaded
Chrome Cache Entry: 286
ASCII text
dropped
Chrome Cache Entry: 287
Unicode text, UTF-8 text
downloaded
Chrome Cache Entry: 288
ASCII text, with very long lines (307)
downloaded
Chrome Cache Entry: 289
CSV text
downloaded
Chrome Cache Entry: 290
PNG image data, 512 x 512, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 291
ASCII text, with very long lines (301)
downloaded
Chrome Cache Entry: 292
Unicode text, UTF-8 text
dropped
Chrome Cache Entry: 293
Unicode text, UTF-8 text, with very long lines (65459)
downloaded
Chrome Cache Entry: 294
ASCII text, with very long lines (12211)
dropped
Chrome Cache Entry: 295
ASCII text
downloaded
Chrome Cache Entry: 296
Unicode text, UTF-8 text
downloaded
Chrome Cache Entry: 297
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 298
ASCII text, with very long lines (65460)
downloaded
Chrome Cache Entry: 299
ASCII text
downloaded
Chrome Cache Entry: 300
ASCII text
downloaded
Chrome Cache Entry: 301
ASCII text, with very long lines (65455)
downloaded
Chrome Cache Entry: 302
Unicode text, UTF-8 text
dropped
Chrome Cache Entry: 303
Unicode text, UTF-8 text, with very long lines (65429)
downloaded
Chrome Cache Entry: 304
ASCII text, with very long lines (686)
dropped
Chrome Cache Entry: 305
ASCII text, with very long lines (495)
downloaded
Chrome Cache Entry: 306
ASCII text, with very long lines (686)
downloaded
Chrome Cache Entry: 307
ASCII text
downloaded
Chrome Cache Entry: 308
ASCII text
dropped
Chrome Cache Entry: 309
Unicode text, UTF-8 text
downloaded
Chrome Cache Entry: 310
Unicode text, UTF-8 text, with very long lines (65435)
downloaded
Chrome Cache Entry: 311
Unicode text, UTF-8 text, with very long lines (65457)
downloaded
Chrome Cache Entry: 312
ASCII text, with very long lines (415)
dropped
Chrome Cache Entry: 313
Web Open Font Format, TrueType, length 66432, version 0.0
downloaded
Chrome Cache Entry: 314
PNG image data, 512 x 512, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 315
Unicode text, UTF-8 text, with very long lines (65457)
dropped
Chrome Cache Entry: 316
Web Open Font Format, TrueType, length 66600, version 0.0
downloaded
Chrome Cache Entry: 317
ASCII text, with very long lines (301)
dropped
Chrome Cache Entry: 318
ASCII text, with very long lines (6362)
downloaded
Chrome Cache Entry: 319
ASCII text
downloaded
Chrome Cache Entry: 320
Unicode text, UTF-8 text, with very long lines (65465)
downloaded
Chrome Cache Entry: 321
CSV text
dropped
Chrome Cache Entry: 322
Unicode text, UTF-8 text, with very long lines (56828)
downloaded
Chrome Cache Entry: 323
ASCII text
downloaded
Chrome Cache Entry: 324
Unicode text, UTF-8 text, with very long lines (65459)
downloaded
Chrome Cache Entry: 325
ASCII text
dropped
Chrome Cache Entry: 326
ASCII text, with very long lines (1612)
downloaded
Chrome Cache Entry: 327
ASCII text
downloaded
Chrome Cache Entry: 328
ASCII text, with very long lines (65467)
downloaded
Chrome Cache Entry: 329
ASCII text, with very long lines (495)
dropped
There are 162 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2092 --field-trial-handle=1928,i,1694561867751154417,9935033051105612894,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://magentacloud.de/s/2bMe7TmEWH89MxG"
malicious
C:\Windows\SysWOW64\unarchiver.exe
"C:\Windows\SysWOW64\unarchiver.exe" "C:\Users\user\Downloads\Jahresbericht STaR 2024.zip"
C:\Windows\SysWOW64\7za.exe
"C:\Windows\System32\7za.exe" x -pinfected -y -o"C:\Users\user\AppData\Local\Temp\j43hmrmm.3cx" "C:\Users\user\Downloads\Jahresbericht STaR 2024.zip"
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\SysWOW64\cmd.exe
"cmd.exe" /C "C:\Users\user\AppData\Local\Temp\j43hmrmm.3cx\Jahresbericht STaR 2024\Jahresbericht_STaR_2024.pdf"
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
"C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\AppData\Local\Temp\j43hmrmm.3cx\Jahresbericht STaR 2024\Jahresbericht_STaR_2024.pdf"
C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
"C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --backgroundcolor=16777215
C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
"C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --log-severity=disable --user-agent-product="ReaderServices/23.6.20320 Chrome/105.0.0.0" --lang=en-US --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2132 --field-trial-handle=1652,i,6175875331327655432,3573518054454937670,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8
There are 1 hidden processes, click here to show them.

URLs

Name
IP
Malicious
https://magentacloud.de/s/2bMe7TmEWH89MxG
https://app.transifex.com/nextcloud/teams/64236/nb_NO/)
unknown
https://app.transifex.com/nextcloud/teams/64236/pt_BR/)
unknown
https://tags-eu.tiqcdn.com/utag/telekom/mediencenter/prod/utag.js?nmcv=41
23.201.253.231
https://magentacloud.de/apps/files/js/fileactions.js?v=541be914-41
80.158.6.204
https://app.transifex.com/nextcloud/teams/64236/zh_TW/)
unknown
https://magentacloud.de/apps/files_sharing/js/public.js?v=541be914-41
80.158.6.204
https://magentacloud.de/apps/viewer/js/viewer-main.js?v=541be914-41
80.158.6.204
https://magentacloud.de/apps/files/js/file-upload.js?v=541be914-41
80.158.6.204
https://app.transifex.com/nextcloud/teams/64236/ru/)
unknown
https://magentacloud.de/apps/theming/theme/light-magenta.css?plain=1&v=48d94615
80.158.6.204
https://github.com/zloirock/core-js
unknown
https://magentacloud.de/js/core/merged-template-prepend.js?v=541be914-41
80.158.6.204
https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/a
unknown
https://app.transifex.com/nextcloud/teams/64236/it/)
unknown
https://magentacloud.de/apps/files/js/semaphore.js?v=541be914-41
80.158.6.204
https://magentacloud.de/apps/files/js/keyboardshortcuts.js?v=541be914-41
80.158.6.204
https://app.transifex.com/nextcloud/teams/64236/ja_JP/)
unknown
https://magentacloud.de/core/css/server.css?v=541be914-41
80.158.6.204
https://app.transifex.com/nextcloud/teams/64236/kab/)
unknown
https://consenthub.utiq.com/
unknown
https://www.telekom.de/impressum
unknown
https://app.transifex.com/nextcloud/teams/64236/ka_GE/)
unknown
https://app.transifex.com/nextcloud/teams/64236/fi_FI/)
unknown
https://magentacloud.de/customapps/nmctheme/js/nmctheme-mimetypes.js?v=541be914-41
80.158.6.204
https://app.transifex.com/nextcloud/teams/64236/cs_CZ/)
unknown
https://app.transifex.com/nextcloud/teams/64236/sr/)
unknown
https://app.transifex.com/nextcloud/teams/64236/sv/)
unknown
https://ebs10.telekom.de/opt-in/icon/utiq.svg
unknown
https://app.transifex.com/nextcloud/teams/64236/fo/)
unknown
https://magentacloud.de/s/2bMe7TmEWH89MxG/download
80.158.6.204
https://magentacloud.de/apps/theming/theme/default.css?plain=1&v=48d94615
80.158.6.204
https://app.transifex.com/nextcloud/teams/64236/hr/)
unknown
https://magentacloud.de/apps/files/css/merged.css?v=d233662f-41
80.158.6.204
https://app.transifex.com/nextcloud/teams/64236/gl/)
unknown
https://magentacloud.de/dist/core-public.js?v=541be914-41
80.158.6.204
https://magentacloud.de/apps/files/js/fileinfomodel.js?v=541be914-41
80.158.6.204
https://magentacloud.de/apps/files/js/newfilemenu.js?v=541be914-41
80.158.6.204
https://ebs10.telekom.de/opt-in/set.php?consent=
unknown
https://magentacloud.de/customapps/nmctheme/fonts/TeleNeoWeb/TeleNeoWeb-Bold.woff
80.158.6.204
https://app.transifex.com/nextcloud/teams/64236/kn/)
unknown
https://magentacloud.de/dist/core-files_fileinfo.js?v=541be914-41
80.158.6.204
https://magentacloud.de/index.php/apps/nmctheme/lang/core/l10n/en.js?v=541be914-41
80.158.6.204
https://magentacloud.de/apps/files_pdfviewer/js/files_pdfviewer-public.js?v=541be914-41
80.158.6.204
https://app.transifex.com/nextcloud/teams/64236/gd/)
unknown
https://magentacloud.de/apps/theming/theme/dark-magenta.css?plain=0&v=48d94615
80.158.6.204
https://app.transifex.com/nextcloud/teams/64236/ig/)
unknown
https://consenthub.utiq.com/pages/privacy-statement
unknown
https://app.transifex.com/nextcloud/teams/64236/de_DE/)
unknown
http://stackoverflow.com/a/20448357
unknown
https://app.transifex.com/nextcloud/teams/64236/la/)
unknown
https://github.com/blueimp/jQuery-File-Upload
unknown
https://magentacloud.de/customapps/nmctheme/fonts/TeleNeoWeb/TeleNeoWeb-Regular.woff
80.158.6.204
https://app.transifex.com/nextcloud/teams/64236/eo/)
unknown
https://magentacloud.de/customapps/nmctheme/js/nmctheme-nmcheader.js?v=541be914-41
80.158.6.204
https://app.transifex.com/nextcloud/teams/64236/ps/)
unknown
https://app.transifex.com/nextcloud/teams/64236/es/)
unknown
https://magentacloud.de/apps/richdocuments/js/richdocuments-reference.js?v=541be914-41
80.158.6.204
https://magentacloud.de/apps/files_sharing/js/templates.js?v=541be914-41
80.158.6.204
https://magentacloud.de/s/2bMe7TmEWH89MxG
80.158.6.204
https://app.transifex.com/nextcloud/teams/64236/de/)
unknown
https://www.telekom.de/ueber-das-unternehmen/datenschutz#drittland-verarbeitung
unknown
https://app.transifex.com/nextcloud/teams/64236/ta/)
unknown
https://magentacloud.de/index.php/apps/nmctheme/lang/nmctheme/l10n/en.js?v=541be914-41
80.158.6.204
https://app.transifex.com/nextcloud/teams/64236/nl/)
unknown
https://app.transifex.com/nextcloud/teams/64236/ur_PK/)
unknown
https://magentacloud.de/index.php/apps/nmctheme/lang/nmcsharing/l10n/en.js?v=541be914-41
80.158.6.204
https://magentacloud.de/apps/text/js/text-viewer.js?v=541be914-41
80.158.6.204
https://magentacloud.de/apps/text/js/text-public.js?v=541be914-41
80.158.6.204
https://app.transifex.com/nextcloud/teams/64236/da/)
unknown
https://blueimp.net
unknown
https://magentacloud.de/apps/files/js/breadcrumb.js?v=541be914-41
80.158.6.204
https://app.transifex.com/nextcloud/teams/64236/ast/)
unknown
https://magentacloud.de/customapps/nmcsettings/js/nmcsettings-nmcsettings.js?v=541be914-41
80.158.6.204
https://www.telekom.de/ueber-das-unternehmen/datenschutz
unknown
https://static.magentacloud.de/analytics/mc_login_tracking.html
unknown
https://magentacloud.de/dist/icons.css
80.158.6.204
https://magentacloud.de/core/js/public/publicpage.js?v=541be914-41
80.158.6.204
http://www.opensource.org/licenses/MIT
unknown
https://app.transifex.com/nextcloud/teams/64236/sw/)
unknown
https://app.transifex.com/nextcloud/teams/64236/uz/)
unknown
https://app.transifex.com/nextcloud/teams/64236/ko/)
unknown
https://app.transifex.com/nextcloud/teams/64236/mr/)
unknown
https://app.transifex.com/nextcloud/teams/64236/zh_CN/)
unknown
https://github.com/zloirock/core-js/blob/v3.25.5/LICENSE
unknown
https://app.transifex.com/nextcloud/teams/64236/kk/)
unknown
https://app.transifex.com/nextcloud/teams/64236/mn/)
unknown
https://app.transifex.com/nextcloud/teams/64236/sc/)
unknown
https://github.com/zloirock/core-js/blob/v3.37.0/LICENSE
unknown
https://magentacloud.de/customapps/nmcsharing/js/nmcsharing-sharing.js?v=541be914-41
80.158.6.204
https://app.transifex.com/nextcloud/teams/64236/ga/)
unknown
https://app.transifex.com/nextcloud/teams/64236/id/)
unknown
https://magentacloud.de/apps/files/js/filemultiselectmenu.js?v=541be914-41
80.158.6.204
https://magentacloud.de/apps/files_sharing/js/public_note.js?v=541be914-41
80.158.6.204
https://app.transifex.com/nextcloud/teams/64236/lb/)
unknown
https://app.transifex.com/nextcloud/teams/64236/ne/)
unknown
https://app.transifex.com/nextcloud/teams/64236/ar/)
unknown
https://app.transifex.com/nextcloud/teams/64236/pl/)
unknown
https://app.transifex.com/nextcloud/teams/64236/ro/)
unknown
https://app.transifex.com/nextcloud/teams/64236/tr/)
unknown
https://magentacloud.de/dist/core-main.js?v=541be914-41
80.158.6.204
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
bg.microsoft.map.fastly.net
199.232.214.172
e8652.dscx.akamaiedge.net
2.23.197.184
magentacloud.de
80.158.6.204
www.google.com
142.250.186.132
e8091.e3.akamaiedge.net
23.201.253.231
tags-eu.tiqcdn.com
unknown
x1.i.lencr.org
unknown

IPs

IP
Domain
Country
Malicious
80.158.3.186
unknown
Germany
192.168.2.8
unknown
unknown
23.201.253.231
e8091.e3.akamaiedge.net
United States
2.23.197.184
e8652.dscx.akamaiedge.net
European Union
239.255.255.250
unknown
Reserved
142.250.186.132
www.google.com
United States
80.158.6.204
magentacloud.de
Germany

Registry

Path
Value
Malicious
HKEY_CURRENT_USER_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe.FriendlyAppName
HKEY_CURRENT_USER_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe.ApplicationCompany

Memdumps

Base Address
Regiontype
Protect
Malicious
960000
heap
page read and write
4EDD000
stack
page read and write
F0E000
stack
page read and write
5630000
heap
page read and write
2BE0000
trusted library allocation
page read and write
587E000
stack
page read and write
4CEE000
stack
page read and write
DB0000
heap
page read and write
ADE000
stack
page read and write
2C18000
trusted library allocation
page read and write
36DE000
stack
page read and write
C62000
trusted library allocation
page execute and read and write
4D10000
trusted library allocation
page execute and read and write
C40000
trusted library allocation
page read and write
59BE000
stack
page read and write
3231000
heap
page read and write
561D000
stack
page read and write
2A20000
heap
page read and write
3BB1000
trusted library allocation
page read and write
2C10000
trusted library allocation
page read and write
3237000
heap
page read and write
DC0000
heap
page read and write
B1E000
heap
page read and write
2BB1000
trusted library allocation
page read and write
324F000
heap
page read and write
2C0C000
trusted library allocation
page read and write
CBE000
stack
page read and write
4D00000
trusted library allocation
page read and write
515E000
stack
page read and write
1088000
heap
page read and write
5880000
heap
page read and write
33D0000
heap
page read and write
2EDC000
stack
page read and write
C77000
trusted library allocation
page execute and read and write
3405000
heap
page read and write
DD0000
trusted library allocation
page read and write
323F000
heap
page read and write
573E000
stack
page read and write
B1B000
heap
page read and write
4DDE000
stack
page read and write
3400000
heap
page read and write
C32000
trusted library allocation
page execute and read and write
127F000
stack
page read and write
107F000
stack
page read and write
D4E000
stack
page read and write
325A000
heap
page read and write
323F000
heap
page read and write
C4C000
trusted library allocation
page execute and read and write
2BEC000
trusted library allocation
page read and write
8F9000
stack
page read and write
8FB000
stack
page read and write
CD0000
heap
page read and write
2C0A000
trusted library allocation
page read and write
3790000
heap
page read and write
2FDC000
stack
page read and write
D90000
heap
page read and write
3340000
heap
page read and write
5580000
heap
page read and write
B10000
heap
page read and write
D00000
heap
page read and write
2C1E000
trusted library allocation
page read and write
505E000
stack
page read and write
323F000
heap
page read and write
100E000
stack
page read and write
33CD000
stack
page read and write
C42000
trusted library allocation
page execute and read and write
C7B000
trusted library allocation
page execute and read and write
3760000
heap
page read and write
980000
heap
page read and write
1080000
heap
page read and write
4F1E000
stack
page read and write
55A0000
heap
page read and write
D00000
heap
page read and write
950000
heap
page read and write
CFD000
stack
page read and write
577E000
stack
page read and write
2C30000
trusted library allocation
page read and write
2B60000
heap
page read and write
2C2E000
trusted library allocation
page read and write
7F730000
trusted library allocation
page execute and read and write
C6A000
trusted library allocation
page execute and read and write
2C05000
trusted library allocation
page read and write
3770000
heap
page read and write
323F000
heap
page read and write
2BFF000
trusted library allocation
page read and write
99C000
stack
page read and write
324F000
heap
page read and write
C3A000
trusted library allocation
page execute and read and write
3237000
heap
page read and write
C20000
trusted library allocation
page read and write
8F6000
stack
page read and write
5EC000
stack
page read and write
3766000
heap
page read and write
985000
heap
page read and write
338E000
unkown
page read and write
1010000
heap
page read and write
3234000
heap
page read and write
2C13000
trusted library allocation
page read and write
B00000
heap
page execute and read and write
2C22000
trusted library allocation
page read and write
DF0000
trusted library allocation
page read and write
323F000
heap
page read and write
E0E000
stack
page read and write
5ABF000
stack
page read and write
D8E000
stack
page read and write
2BFA000
trusted library allocation
page read and write
4BEE000
stack
page read and write
B4E000
heap
page read and write
B38000
heap
page read and write
2C16000
trusted library allocation
page read and write
A9E000
stack
page read and write
2B65000
heap
page read and write
501D000
stack
page read and write
C4A000
trusted library allocation
page execute and read and write
35DE000
unkown
page read and write
3220000
heap
page read and write
10C0000
heap
page read and write
There are 107 hidden memdumps, click here to show them.