IOCReport

loading gif

Files

File Path
Type
Category
Malicious
MALWARE ACH WIRE PAYMENT ADVICE..xlsx
Microsoft Excel 2007+
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4O403JZ\ZlFRrg5s[1].htm
HTML document, UTF-8 Unicode text, with very long lines
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XNHC0JWC\ZlFRrg5s[1].htm
HTML document, UTF-8 Unicode text, with very long lines
dropped
malicious
C:\Users\user\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
PNG image data, 16 x 16, 4-bit colormap, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\MP98E46N\24mbw17feyn.typeform[1].xml
ASCII text, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{06357C73-5634-11EB-ADCF-ECF4BBB5915B}.dat
Microsoft Word Document
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{0B7414B4-5634-11EB-ADCF-ECF4BBB5915B}.dat
Microsoft Word Document
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{06357C75-5634-11EB-ADCF-ECF4BBB5915B}.dat
Microsoft Word Document
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{0B7414B6-5634-11EB-ADCF-ECF4BBB5915B}.dat
Microsoft Word Document
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{0B7414B7-5634-11EB-ADCF-ECF4BBB5915B}.dat
Microsoft Word Document
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore\lr5drzg\imagestore.dat
data
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5JC0A1KN\dnserror[1]
HTML document, UTF-8 Unicode (with BOM) text, with CRLF line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5JC0A1KN\favicon[1].ico
PNG image data, 16 x 16, 4-bit colormap, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5JC0A1KN\httpErrorPagesScripts[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4O403JZ\LnkQ4hGmxTTD[1].png
PNG image data, 131 x 109, 8-bit/color RGBA, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4O403JZ\favicon-32x32[1].png
PNG image data, 32 x 32, 8-bit gray+alpha, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4O403JZ\urlblockindex[1].bin
data
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XNHC0JWC\aa6e0ec721[1].js
ASCII text, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XNHC0JWC\aa6e0ec721[2].js
ASCII text, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XNHC0JWC\errorPageStrings[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\NewErrorPageTemplate[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\large[1].jpg
JPEG image data, baseline, precision 8, 1920x1080, frames 3
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\nr-1123.min[1].js
ASCII text, with very long lines, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\B24727B2.jpeg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 816x1056, frames 3
dropped
clean
C:\Users\user\AppData\Local\Temp\~DF0E06319D83AC7A0C.TMP
data
dropped
clean
C:\Users\user\AppData\Local\Temp\~DF37DFCB5A035E701F.TMP
data
dropped
clean
C:\Users\user\AppData\Local\Temp\~DF603759FFBDDCD7CD.TMP
data
dropped
clean
C:\Users\user\AppData\Local\Temp\~DFE817CF54CF726A92.TMP
data
dropped
clean
C:\Users\user\AppData\Local\Temp\~DFF6708434B88E8000.TMP
data
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\BPMGT7B2.txt
ASCII text
downloaded
clean
C:\Users\user\Desktop\~$MALWARE ACH WIRE PAYMENT ADVICE..xlsx
data
dropped
clean
There are 21 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
clean
C:\Program Files\Internet Explorer\iexplore.exe
'C:\Program Files\Internet Explorer\iexplore.exe' -Embedding
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:2528 CREDAT:275457 /prefetch:2
clean
C:\Program Files\Internet Explorer\iexplore.exe
'C:\Program Files\Internet Explorer\iexplore.exe' https://24mbw17feyn.typeform.com/to/ZlFRrg5s
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:1836 CREDAT:275457 /prefetch:2
clean

URLs

Name
IP
Malicious
https://www.typeform.com/?utm_campaign=undefined&utm_source=typeform.com-17520522-Free&utm_medium=typeform&utm_content=typeform-closescreen&utm_term=EN
clean
https://images.typeform.com/images/CJr828dpN5yQ/image/default
unknown
clean
https://public-assets.typeform.com/public/favicon/favicon-32x32.png
unknown
clean
https://images.typeform.com/images/nXkRcNPp6wtg/background/large
unknown
clean
https://public-assets.typeform.com/public/favicon/safari-pinned-tab.svg
unknown
clean
https://24mbw17feyn.typeform.com/to/ZlFRrg5s6MlCR0S0FT
unknown
clean
https://24mbw17feyn.typeform.com/to/ZlFRrg5s
unknown
clean
https://24mbw17feyn.typeform.com/to/ZlFRrg5s6om/?utm_campaign=undefined&utm_sorm.com/to/ZlFRrg5s
unknown
clean
https://24mbw17feyn.ty
unknown
clean
https://24mbw17feyn.typeform.com/oembed?url=https%3A%2F%2F24mbw17feyn.typeform.com%2Fto%2FZlFRrg5s
unknown
clean
https://public-assets.typeform.com/public/favicon/favicon-16x16.png
unknown
clean
https://24mbw17feyn.typeform.com/to/ZlFRrg5s6peform.com/to/ZlFRrg5sRoot
unknown
clean
https://24mbw17feyn.typeform.com/to/ZlFRrg5s
clean
https://images.typeform.com/images/nXkRcNPp6wtg/background/large);background-position:top
unknown
clean
https://24mbw17feyn.typeform.com/to/ZlFRrg5s6Root
unknown
clean
https://images.typeform.com/images/FYUps4mFKPYK/image/default
unknown
clean
https://public-assets.typeform.com/public/favicon/browserconfig.xml
unknown
clean
https://public-assets.typeform.com/public/favicon/site.webmanifest
unknown
clean
https://public-assets.typeform.com/public/favicon/favicon.ico
unknown
clean
https://24mbw17feyn.typeform.com/to/ZlFRrg5sz
unknown
clean
https://public-assets.typeform.com/public/favicon/apple-touch-icon.png
unknown
clean
https://24mbw17feyn.typeform.com/to/ZlFRrg5s/favicon-32x32.png
unknown
clean
https://www.typeform.c
unknown
clean
https://24mbw17feyn.typeform.com/to/ZlFRrg5sRoot
unknown
clean
https://public-assets.typeform.com/public/favicon/favicon-32x32.png-
unknown
clean
https://www.typeform.com/?utm_campaign=undefined&utm_source=typeform.com-17520522-Free&utm_medium=ty
unknown
clean
https://www.typeform.com/?utm_campaign=undefined&utm_source=typeform.com-17520522-Free&utm_m
unknown
clean
There are 17 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
d2nvsmtq2poimt.cloudfront.net
65.9.58.100
clean
bam.nr-data.net
162.247.242.20
clean
d2p6vz8nayi9a3.cloudfront.net
65.9.58.120
clean
public-assets.typeform.com
unknown
clean
js-agent.newrelic.com
unknown
clean
images.typeform.com
unknown
clean
24mbw17feyn.typeform.com
unknown
clean

IPs

IP
Domain
Country
Active
Malicious
65.9.58.100
unknown
United States
unknown
clean
65.9.58.120
unknown
United States
unknown
clean
162.247.242.20
unknown
United States
unknown
clean
65.9.58.89
unknown
United States
unknown
clean

Registry

Path
Value
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
l!2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
MTTT
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ReviewToken
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ED04A
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
VBAFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DefaultSheetR2L
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
UseSystemSeparators
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ThousandsSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DecimalSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
=&2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F3312
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F34F5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
UseRWHlinkNavigation
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
@%SystemRoot%\system32\qagentrt.dll,-10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
@%SystemRoot%\System32\fveui.dll,-843
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
@%SystemRoot%\System32\fveui.dll,-844
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
@%SystemRoot%\System32\wuaueng.dll,-400
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
{17FE9752-0B5A-4665-84CD-569794602F5C} {7F9185B0-CB92-43C5-80A9-92277A4F7B54} 0xFFFF
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
LastPurgeTime
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EXCELFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SavedLegacySettings
clean
C:\Program Files\Internet Explorer\iexplore.exe
{06357C73-5634-11EB-ADCF-ECF4BBB5915B}
clean
C:\Program Files\Internet Explorer\iexplore.exe
ChangeNotice
clean
C:\Program Files\Internet Explorer\iexplore.exe
NextUpdateDate
clean
C:\Program Files\Internet Explorer\iexplore.exe
NextCheckForUpdateLowDateTime
clean
C:\Program Files\Internet Explorer\iexplore.exe
NextCheckForUpdateHighDateTime
clean
C:\Program Files\Internet Explorer\iexplore.exe
SavedLegacySettings
clean
C:\Program Files\Internet Explorer\iexplore.exe
Count
clean
C:\Program Files\Internet Explorer\iexplore.exe
Time
clean
C:\Program Files\Internet Explorer\iexplore.exe
LoadTimeArray
clean
C:\Program Files\Internet Explorer\iexplore.exe
88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977
clean
C:\Program Files\Internet Explorer\iexplore.exe
2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81
clean
C:\Program Files\Internet Explorer\iexplore.exe
DecayDateQueue
clean
C:\Program Files\Internet Explorer\iexplore.exe
LastProcessed
clean
C:\Program Files\Internet Explorer\iexplore.exe
NextCheckForUpdateLowDateTime
clean
C:\Program Files\Internet Explorer\iexplore.exe
NextCheckForUpdateHighDateTime
clean
C:\Program Files\Internet Explorer\iexplore.exe
DecayDateQueue
clean
C:\Program Files\Internet Explorer\iexplore.exe
LastProcessed
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
NumberOfSubdomains
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
@C:\Windows\System32\ieframe.dll,-912
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
@C:\Windows\System32\ieframe.dll,-904
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
SavedLegacySettings
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
Blob
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
Blob
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
Blob
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
Blob
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
Blob
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
Blob
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
Blob
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
Blob
clean
C:\Program Files\Internet Explorer\iexplore.exe
{0B7414B4-5634-11EB-ADCF-ECF4BBB5915B}
clean
C:\Program Files\Internet Explorer\iexplore.exe
SavedLegacySettings
clean
C:\Program Files\Internet Explorer\iexplore.exe
Window_Placement
clean
C:\Program Files\Internet Explorer\iexplore.exe
AdminActive
clean
C:\Program Files\Internet Explorer\iexplore.exe
AdminActive
clean
C:\Program Files\Internet Explorer\iexplore.exe
Count
clean
C:\Program Files\Internet Explorer\iexplore.exe
Time
clean
C:\Program Files\Internet Explorer\iexplore.exe
LoadTimeArray
clean
C:\Program Files\Internet Explorer\iexplore.exe
88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977
clean
C:\Program Files\Internet Explorer\iexplore.exe
2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81
clean
C:\Program Files\Internet Explorer\iexplore.exe
Count
clean
C:\Program Files\Internet Explorer\iexplore.exe
Time
clean
C:\Program Files\Internet Explorer\iexplore.exe
LoadTimeArray
clean
C:\Program Files\Internet Explorer\iexplore.exe
NextUpdateDate
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
SavedLegacySettings
clean
There are 118 hidden registries, click here to show them.

DOM / HTML

URL
Malicious
https://24mbw17feyn.typeform.com/to/ZlFRrg5s
malicious
https://www.typeform.com/?utm_campaign=undefined&utm_source=typeform.com-17520522-Free&utm_medium=typeform&utm_content=typeform-closescreen&utm_term=EN
clean