Malicious
Classifications
Spyware
Threat Names
VBS.Heur.ObfDldr.30.6277A94D.Gen
Dynamic Analysis Report
Created on 2021-06-23T22:24:00
Miembros de la UNAB para arrestar.docx
Word Document
Remarks (1/1)
(0x0200003A): A task was rescheduled ahead of time to reveal dormant functionality.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
File Name | Category | Type | Verdict | Actions |
---|
C:\Users\kEecfMwgj\Desktop\Miembros de la UNAB para arrestar.docx | Sample File | Word Document |
malicious
|
...
|
»
Office Information
»
Creator | GEHRIUC |
Last Modified By | JVBRQ |
Revision | 2 |
Create Time | 2019-03-16 10:47:00+00:00 |
Modify Time | 2019-11-02 18:29:00+00:00 |
Application | Microsoft Office Word |
App Version | 16.0000 |
Template | template48.dot |
Document Security | NONE |
Editing Time | 94.0 |
Page Count | 1 |
Line Count | 1 |
Paragraph Count | 1 |
Character Count | 1 |
Chars With Spaces | 1 |
ScaleCrop | |
SharedDoc |
Extracted Image Texts (1)
»
Image 1: image1.png
»
]] Office
‘1 documento esta protegido
1. Abra el documento en el Microsoft Office. Para los
documente
sin proteccion no hay accesso on-line
2. En el caso de cargar el documento de su correo pulse
la tecla “Permutir edicion” en la raya amarilla de arriba
3. Haber permitido la edicion pulse la tecla “Incluir
contenido” en la raya amarilla de arriba
Extracted URLs (1)
»
URL | WHOIS Data | Reputation Status | Recursively Submitted | Actions |
---|---|---|---|---|
https://templateworkshop.site:44567/template_storage/normal_template/template48.dot |
Show WHOIS
|
N/A
|
- |
...
|
C:\Users\kEecfMwgj\AppData\Local\Microsoft\OneDriveUpdate.vbs | Dropped File | Text |
malicious
|
...
|
»
AV Matches (1)
»
Threat Name | Verdict |
---|---|
VBS.Heur.ObfDldr.30.6277A94D.Gen |
malicious
|
c:\users\keecfmwgj\appdata\local\microsoft\office\16.0\officefilecache\centraltable.laccdb | Modified File | Stream |
clean
|
...
|
»
c:\users\keecfmwgj\desktop\~wrd0000.tmp | Dropped File | Word Document |
clean
|
...
|
»
Office Information
»
Creator | GEHRIUC |
Last Modified By | kEecfMwgj |
Revision | 3 |
Create Time | 2019-03-16 10:47:00+00:00 |
Modify Time | 2021-06-23 22:25:00+00:00 |
Application | Microsoft Office Word |
App Version | 16.0000 |
Template | template48 |
Document Security | NONE |
Editing Time | 94.0 |
Page Count | 1 |
Line Count | 1 |
Paragraph Count | 1 |
Character Count | 1 |
Chars With Spaces | 1 |
ScaleCrop | |
SharedDoc |
Extracted URLs (1)
»
URL | WHOIS Data | Reputation Status | Recursively Submitted | Actions |
---|---|---|---|---|
https://templateworkshop.site:44567/template_storage/normal_template/template48.dot |
Show WHOIS
|
N/A
|
- |
...
|
c:\users\keecfmwgj\appdata\local\microsoft\windows\temporary internet files\content.mso\d8b38049.png | Dropped File | Unknown |
clean
|
...
|
»
c:\users\keecfmwgj\appdata\local\temp\tryrthhfghfhgffgg.tmp | Dropped File | Stream |
clean
|
...
|
»
C:\Users\KEECFM~1\AppData\Local\Temp\nohitatusbkwu.tmp | Dropped File | Image |
clean
|
...
|
»
e238799016988449395e1588f65a75c996efb887d5395f5807527910239e7416 | Downloaded File | Text |
clean
|
...
|
»
74188468490e859f321fa79343591c6c0a4880d3f77a5cab99298d5e2d6c2c42 | Downloaded File | Text |
clean
Known to be clean.
|
...
|
»