Sorry if this is the same as the others youve had in the past few hours but these two says it comes from system32 and windows and is thus very spooky to me
Malwarebytes
www.malwarebytes.com
-Log Details-
Protection Event Date: 02/04/2021
Protection Event Time: 18:37
Log File: 170a8e40-93da-11eb-bbc9-d8cb8ac44f21.json
-Software Information-
Version: 4.3.0.98
Components Version: 1.0.1217
Update Package Version: 1.0.39014
Licence: Premium
-System Information-
OS: Windows 10 (Build 19041.867)
CPU: x64
File System: NTFS
User: System
-Blocked Website Details-
Malicious Website: 1
, C:\Windows\System32\svchost.exe, Blocked, -1, -1, 0.0.0, ,
-Website Data-
Category: Trojan
Domain: cs9.wac.phicdn.net
IP Address: 93.184.220.29
Port: 80
Type: Outbound
File: C:\Windows\System32\svchost.exe
(end)
and
Malwarebytes
www.malwarebytes.com
-Log Details-
Protection Event Date: 02/04/2021
Protection Event Time: 17:48
Log File: 3572338a-93d3-11eb-a01d-d8cb8ac44f21.json
-Software Information-
Version: 4.3.0.98
Components Version: 1.0.1217
Update Package Version: 1.0.39014
Licence: Premium
-System Information-
OS: Windows 10 (Build 19041.867)
CPU: x64
File System: NTFS
User: System
-Blocked Website Details-
Malicious Website: 1
, C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe, Blocked, -1, -1, 0.0.0, ,
-Website Data-
Category: Trojan
Domain: cs9.wac.phicdn.net
IP Address: 93.184.220.29
Port: 80
Type: Outbound
File: C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(end)