Time;Scanner;Object type;Object;Threat;Action;User;Information;Hash;First seen here
6/27/2017 11:22:00 AM;Real-time file system protection;file;C:\Users\AIRWORX 2\AppData\Roaming\Belkasoft\Evidence Center\New case (2017.06.27 08_31_06)\New case (2017.06.27 08 31 06)\65\embeddedfile\4\1367.pdf;PDF/Phishing.Agent.ABA trojan;cleaned by deleting;AIRWORX2-PC\AIRWORX 2;Event occurred on a file modified by the application: C:\Program Files (x86)\Belkasoft Evidence Center Ultimate\stub\ApplicationClient.exe (70B099C81CE54045D4283DA61A363AFB0FF7DAAD).;14B53EF55E205B16335A3FBF6F821329092FEF33;6/27/2017 11:19:21 AM
6/27/2017 11:35:06 AM;Real-time file system protection;file;C:\Users\AIRWORX 2\AppData\Roaming\Belkasoft\Evidence Center\New case (2017.06.27 08_31_06)\New case (2017.06.27 08 31 06)\65\embeddedfile\4\1754.doc;VBA/TrojanDropper.Agent.FT trojan;cleaned;AIRWORX2-PC\AIRWORX 2;Event occurred on a file modified by the application: C:\Program Files (x86)\Belkasoft Evidence Center Ultimate\stub\ApplicationClient.exe (70B099C81CE54045D4283DA61A363AFB0FF7DAAD).;45E856B5D954D0F52ABB6964738353767BC08EB3;6/27/2017 11:35:05 AM
6/29/2017 10:16:27 AM;Real-time file system protection;file;C:\CCSupport\Tools\ESETFunctionalityTester\Temp\eicar.txt;Eicar test file;cleaned by deleting;NT AUTHORITY\SYSTEM;Event occurred on a new file created by the application: C:\Windows\System32\mshta.exe (1C893D6150E0A8C0E16AE16DB8988387C1BEB871).;3395856CE81F2B7382DEE72602F798B642F14140;6/29/2017 10:16:27 AM
6/29/2017 10:16:31 AM;HTTP filter;file;
http://amtso.securit...Win32/PUAtest.Bpotentially unwanted application;connection terminated;NT AUTHORITY\SYSTEM;Threat was detected upon access to web by the application: C:\Windows\System32\mshta.exe (1C893D6150E0A8C0E16AE16DB8988387C1BEB871).;00117F70C86ADB0F979021391A8AEAA497C2C8DF;6/29/2017 10:16:31 AM
6/29/2017 10:16:34 AM;HTTP filter;file;
http://amtso.securit....exe;SuspiciousObject;connection terminated;NT AUTHORITY\SYSTEM;Threat was detected upon access to web by the application: C:\Windows\System32\mshta.exe (1C893D6150E0A8C0E16AE16DB8988387C1BEB871).;F4053231135502B4E8EA2B4D2E32ABEFE3A08765;6/29/2017 10:16:34 AM
7/12/2017 2:17:07 AM;Email filter - Outlook;email message;from:
[email protected] to:
[email protected] with subject Status of your UPS delivery ID:08653334 ;a variant of JS/Danger.ScriptAttachment trojan;contained infected files;AIRWORX2-PC\AIRWORX 2;;;
7/18/2017 1:56:53 PM;Real-time file system protection;file;C:\WINDOWS\TEMP\ioc937F3E0A-B80D-B148-9D57-187643393794.js;JS/TrojanDownloader.Nemucod.COL trojan;cleaned by deleting;AIRWORX2-PC\AIRWORX 2;Event occurred on a new file created by the application: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\avp.exe (135BEBD69E79622FBADB8859598520312301BE88).;786E6090054F269C28CF1EBDFBBAF8B5C30D845B;7/18/2017 1:56:42 PM
7/18/2017 1:57:01 PM;Real-time file system protection;file;C:\WINDOWS\TEMP\ioc4B0FC8B8-A8F4-764B-BE1A-30C01C27205B.js;JS/TrojanDownloader.Nemucod.COL trojan;cleaned by deleting;AIRWORX2-PC\AIRWORX 2;Event occurred on a new file created by the application: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\avp.exe (135BEBD69E79622FBADB8859598520312301BE88).;786E6090054F269C28CF1EBDFBBAF8B5C30D845B;7/18/2017 1:56:52 PM
7/18/2017 4:05:14 PM;Real-time file system protection;file;C:\WINDOWS\TEMP\ioc9C993D64-BF7B-5F4A-AA6D-7D51C2CCAEDD.js;JS/TrojanDownloader.Nemucod.CUP trojan;cleaned by deleting;AIRWORX2-PC\AIRWORX 2;Event occurred on a new file created by the application: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\avp.exe (135BEBD69E79622FBADB8859598520312301BE88).;EB4BE79C7E57C3540A34EB74892E955D1C90CA05;7/18/2017 4:05:00 PM
7/18/2017 8:34:15 PM;Real-time file system protection;file;C:\WINDOWS\TEMP\iocB3A2BAD4-6975-BA45-9451-9A9CC7640F52.js;JS/TrojanDownloader.Nemucod.COL trojan;cleaned by deleting;AIRWORX2-PC\AIRWORX 2;Event occurred on a new file created by the application: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\avp.exe (135BEBD69E79622FBADB8859598520312301BE88).;786E6090054F269C28CF1EBDFBBAF8B5C30D845B;7/18/2017 8:34:01 PM
7/18/2017 8:34:18 PM;Real-time file system protection;file;C:\WINDOWS\TEMP\ioc78C7BA79-CF23-FE43-AD88-94D68A7A2200.js;JS/TrojanDownloader.Nemucod.COL trojan;cleaned by deleting;AIRWORX2-PC\AIRWORX 2;Event occurred on a new file created by the application: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\avp.exe (135BEBD69E79622FBADB8859598520312301BE88).;786E6090054F269C28CF1EBDFBBAF8B5C30D845B;7/18/2017 8:34:11 PM
7/18/2017 10:37:48 PM;Real-time file system protection;file;C:\WINDOWS\TEMP\ioc1C2A81EF-4D6C-514E-BC04-67EB6DC10E79.js;JS/TrojanDownloader.Nemucod.CUP trojan;cleaned by deleting;AIRWORX2-PC\AIRWORX 2;Event occurred on a new file created by the application: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\avp.exe (135BEBD69E79622FBADB8859598520312301BE88).;EB4BE79C7E57C3540A34EB74892E955D1C90CA05;7/18/2017 10:37:36 PM
7/18/2017 11:46:38 PM;Real-time file system protection;file;C:\WINDOWS\TEMP\ioc57BAFF42-B365-9D40-9E28-E873F79A626F.js;JS/TrojanDownloader.Nemucod.COL trojan;cleaned by deleting;AIRWORX2-PC\AIRWORX 2;Event occurred on a new file created by the application: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\avp.exe (135BEBD69E79622FBADB8859598520312301BE88).;786E6090054F269C28CF1EBDFBBAF8B5C30D845B;7/18/2017 11:46:26 PM
7/18/2017 11:46:42 PM;Real-time file system protection;file;C:\WINDOWS\TEMP\ioc494B2523-387F-864D-ADCB-F758646E6B23.js;JS/TrojanDownloader.Nemucod.COL trojan;cleaned by deleting;AIRWORX2-PC\AIRWORX 2;Event occurred on a new file created by the application: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\avp.exe (135BEBD69E79622FBADB8859598520312301BE88).;786E6090054F269C28CF1EBDFBBAF8B5C30D845B;7/18/2017 11:46:37 PM
7/19/2017 1:20:28 AM;Real-time file system protection;file;C:\WINDOWS\TEMP\ioc8C9E1821-7C50-314D-B1ED-078F5FDFA437.js;JS/TrojanDownloader.Nemucod.CUP trojan;cleaned by deleting;AIRWORX2-PC\AIRWORX 2;Event occurred on a new file created by the application: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\avp.exe (135BEBD69E79622FBADB8859598520312301BE88).;EB4BE79C7E57C3540A34EB74892E955D1C90CA05;7/19/2017 1:20:13 AM
7/19/2017 2:50:30 AM;Real-time file system protection;file;C:\WINDOWS\TEMP\ioc32C04CA4-EF00-E646-91B0-A70E6671D2B0.js;JS/TrojanDownloader.Nemucod.COL trojan;cleaned by deleting;AIRWORX2-PC\AIRWORX 2;Event occurred on a new file created by the application: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\avp.exe (135BEBD69E79622FBADB8859598520312301BE88).;786E6090054F269C28CF1EBDFBBAF8B5C30D845B;7/19/2017 2:50:20 AM
7/19/2017 2:50:30 AM;Real-time file system protection;file;C:\WINDOWS\TEMP\iocBF9A5302-E4DF-1043-852C-52D02451400E.js;JS/TrojanDownloader.Nemucod.COL trojan;cleaned by deleting;AIRWORX2-PC\AIRWORX 2;Event occurred on a new file created by the application: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\avp.exe (135BEBD69E79622FBADB8859598520312301BE88).;786E6090054F269C28CF1EBDFBBAF8B5C30D845B;7/19/2017 2:50:10 AM
7/19/2017 3:59:35 AM;Real-time file system protection;file;C:\WINDOWS\TEMP\ioc8A0CA6E1-8C7A-F14B-9021-9E4ECBFAD9BB.js;JS/TrojanDownloader.Nemucod.CUP trojan;cleaned by deleting;AIRWORX2-PC\AIRWORX 2;Event occurred on a new file created by the application: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\avp.exe (135BEBD69E79622FBADB8859598520312301BE88).;EB4BE79C7E57C3540A34EB74892E955D1C90CA05;7/19/2017 3:59:20 AM
7/19/2017 7:21:10 AM;Real-time file system protection;file;C:\WINDOWS\TEMP\ioc24BEF7A2-779E-F240-B8A6-8AE30F1105D3.js;JS/TrojanDownloader.Nemucod.COL trojan;cleaned by deleting;AIRWORX2-PC\AIRWORX 2;Event occurred on a new file created by the application: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\avp.exe (135BEBD69E79622FBADB8859598520312301BE88).;786E6090054F269C28CF1EBDFBBAF8B5C30D845B;7/19/2017 7:20:50 AM
7/19/2017 7:21:10 AM;Real-time file system protection;file;C:\WINDOWS\TEMP\ioc1AEE3120-404F-7A43-944D-5D11F3E9491B.js;JS/TrojanDownloader.Nemucod.COL trojan;cleaned by deleting;AIRWORX2-PC\AIRWORX 2;Event occurred on a new file created by the application: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\avp.exe (135BEBD69E79622FBADB8859598520312301BE88).;786E6090054F269C28CF1EBDFBBAF8B5C30D845B;7/19/2017 7:21:00 AM
7/19/2017 8:31:01 AM;Real-time file system protection;file;C:\WINDOWS\TEMP\iocB1D3812B-4C31-0042-980E-92D1BC704475.js;JS/TrojanDownloader.Nemucod.COL trojan;cleaned by deleting;AIRWORX2-PC\AIRWORX 2;Event occurred on a new file created by the application: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\avp.exe (135BEBD69E79622FBADB8859598520312301BE88).;786E6090054F269C28CF1EBDFBBAF8B5C30D845B;7/19/2017 8:30:40 AM
7/19/2017 8:31:01 AM;Real-time file system protection;file;C:\WINDOWS\TEMP\ioc880FC18D-01A9-AC46-A4C8-BE26B8BAF410.js;JS/TrojanDownloader.Nemucod.COL trojan;cleaned by deleting;AIRWORX2-PC\AIRWORX 2;Event occurred on a new file created by the application: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\avp.exe (135BEBD69E79622FBADB8859598520312301BE88).;786E6090054F269C28CF1EBDFBBAF8B5C30D845B;7/19/2017 8:30:50 AM
7/21/2017 12:10:26 PM;Real-time file system protection;file;C:\WINDOWS\TEMP\ioc329B01BE-B480-AA47-B266-EF6416742028.js;JS/TrojanDownloader.Nemucod.COL trojan;cleaned by deleting;AIRWORX2-PC\AIRWORX 2;Event occurred on a new file created by the application: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\avp.exe (135BEBD69E79622FBADB8859598520312301BE88).;786E6090054F269C28CF1EBDFBBAF8B5C30D845B;7/21/2017 12:10:04 PM
7/21/2017 12:10:29 PM;Real-time file system protection;file;C:\WINDOWS\TEMP\ioc4CA18A5F-1A8C-BC42-A92A-9E651A083F7A.js;JS/TrojanDownloader.Nemucod.COL trojan;cleaned by deleting;AIRWORX2-PC\AIRWORX 2;Event occurred on a new file created by the application: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\avp.exe (135BEBD69E79622FBADB8859598520312301BE88).;786E6090054F269C28CF1EBDFBBAF8B5C30D845B;7/21/2017 12:10:14 PM
7/21/2017 2:34:03 PM;Real-time file system protection;file;C:\WINDOWS\TEMP\ioc48BC09CE-F645-8747-8A47-2B5267E8BA17.js;JS/TrojanDownloader.Nemucod.COL trojan;cleaned by deleting;AIRWORX2-PC\AIRWORX 2;Event occurred on a new file created by the application: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\avp.exe (135BEBD69E79622FBADB8859598520312301BE88).;786E6090054F269C28CF1EBDFBBAF8B5C30D845B;7/21/2017 2:33:45 PM
7/21/2017 2:34:05 PM;Real-time file system protection;file;C:\WINDOWS\TEMP\ioc1B5CD64B-6AA1-F049-AA96-7FF13B7EDBF6.js;JS/TrojanDownloader.Nemucod.COL trojan;cleaned by deleting;AIRWORX2-PC\AIRWORX 2;Event occurred on a new file created by the application: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\avp.exe (135BEBD69E79622FBADB8859598520312301BE88).;786E6090054F269C28CF1EBDFBBAF8B5C30D845B;7/21/2017 2:33:55 PM