GridinSoft Threat Intelligence
doc_start.js file report
Why it matters
Evidence available for this file
No final classification is available yet.
First seen 2017-05-24 12:04:35 (9 years ago); latest analysis 2021-04-12 20:15:15 (5 years ago).
ThreatInfo has seen this file in user or system paths listed below. Unexpected locations increase the need for local verification.
Recommended action
What to do next
- Use the hash and metadata below to verify the exact file identity.
- Review publisher, signature, paths, and PE details for inconsistencies.
- Run a local scan if the file appears unexpectedly or starts with Windows.
File context
doc_start.js is a Windows file recorded in the ThreatInfo database. The current detection status is Undefined, based on the latest analysis from 2021-04-12 20:15:15 (5 years ago).
ThreatInfo does not have a final classification for this file yet. Use the technical details below to compare the hash, size, signature, and observed locations with the copy found on your device.
File Details
| MD5: | 8d363f1a2c736dbb0a5efbc32eabbf5d |
| Size: | 472 bytes |
| First Published: | 2017-05-24 12:04:35 (9 years ago) |
| Latest Published: | 2021-04-12 20:15:15 (5 years ago) |
| Status: | Undefined (on last analysis) | |
| Analysis Date: | 2021-04-12 20:15:15 (5 years ago) |
Common Places:
| %localappdata%\proquy\chromedefaultdata\extensions\nlbjncdgjeocebhnmkbbbdekmmmcbfjd\2.2.4_0 |
| %localappdata%\ucozmedia\uran\user data\default\extensions\nlbjncdgjeocebhnmkbbbdekmmmcbfjd\2.2.4_0 |
| %localappdata%\ucozmedia\uran\user data\default\extensions\nlbjncdgjeocebhnmkbbbdekmmmcbfjd\2.2.4_1 |
| %localappdata%\ucozmedia\uran\user data\default\extensions\nlbjncdgjeocebhnmkbbbdekmmmcbfjd |
| %localappdata%\ucbrowser\user data_i18n\default\extensions\nlbjncdgjeocebhnmkbbbdekmmmcbfjd |
| %profile%\dmin\local settings\application data\ucozmedia\uran\user data\default\extensions\nlbjncdgjeocebhnmkbbbdekmmmcbfjd |
| %localappdata%\ucozmedia\uran\user data\profile 1\extensions\nlbjncdgjeocebhnmkbbbdekmmmcbfjd |
| %localappdata%\uran\user data\default\extensions\nlbjncdgjeocebhnmkbbbdekmmmcbfjd |
| %chromeprofile%\extensions\nlbjncdgjeocebhnmkbbbdekmmmcbfjd |
| %appdata%\baidu\spark\profile\extensions\nlbjncdgjeocebhnmkbbbdekmmmcbfjd |
ThreatInfo has observed doc_start.js in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.
Geographic signal
Observed country distribution
ThreatInfo has seen doc_start.js across 30 countries. Use this signal to compare local evidence with where the sample is most often reported.
The strongest geographic signal for this file is Russian Federation with 37.1% of observed hits. Geographic distribution can help identify targeted campaigns, regional software bundles, or where a file is most commonly reported.
OS Version:
The most common operating system signal for doc_start.js is Windows 10 with 51.3% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.
Analysis
Report conclusion
This file is still under review
ThreatInfo has not assigned a final verdict yet. Compare the file hash, location, signature, and publisher before trusting the file on a production system.