IOCReport

loading gif

Files

File Path
Type
Category
Malicious
case (1522).xls
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1251, Author: , Last Saved By: , Name of Creating Application: Microsoft Excel, Last Printed: Tue Jan 26 16:17:13 2021, Create Time/Date: Thu Apr 23 13:26:24 2020, Last Saved Time/Date: Tue Jan 26 16:28:15 2021, Security: 0
initial sample
malicious
C:\ProgramData\formnet.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4O403JZ\scfrd[1].dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
downloaded
malicious
C:\Users\user\AppData\Local\Temp\B6EE0000
data
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Desktop.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Read-Only, Directory, ctime=Tue Oct 17 10:04:00 2017, mtime=Wed Jan 27 04:31:44 2021, atime=Wed Jan 27 04:31:44 2021, length=12288, window=hide
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\case (1522).LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Wed Aug 26 14:08:15 2020, mtime=Wed Jan 27 04:31:44 2021, atime=Wed Jan 27 04:31:44 2021, length=99328, window=hide
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
ASCII text, with CRLF line terminators
modified
clean
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\B8J2SM51.txt
ASCII text
downloaded
clean
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\SCG1PMXY.txt
ASCII text
downloaded
clean
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\TK4XJNTQ.txt
ASCII text
downloaded
clean
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\WG4KTJBM.txt
ASCII text
downloaded
clean
C:\Users\user\AppData\Roaming\Ytziy\ipnyw.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\Desktop\77EE0000
Applesoft BASIC program data, first line number 16
dropped
clean
There are 3 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
malicious
C:\Windows\System32\rundll32.exe
'C:\Windows\System32\rundll32.exe' C:\ProgramData\formnet.dll,DllRegisterServer
malicious
C:\Windows\SysWOW64\rundll32.exe
'C:\Windows\System32\rundll32.exe' C:\ProgramData\formnet.dll,DllRegisterServer
malicious
C:\Windows\SysWOW64\msiexec.exe
msiexec.exe
clean

URLs

Name
IP
Malicious
https://rnollg.com/kev/scfrd.dll
unknown
malicious
http://wmwifbajxxbcxmucxmlc.com/files/april24.dll)
unknown
clean
http://www.windows.com/pctv.
unknown
clean
http://investor.msn.com
unknown
clean
http://www.msnbc.com/news/ticker.txt
unknown
clean
http://crl.entrust.net/server1.crl0
unknown
clean
https://govemedico.tk/7
unknown
clean
http://crl3.digicert
unknown
clean
http://ocsp.entrust.net03
unknown
clean
https://homesoapmolds.com/post.phpr
unknown
clean
http://crl.pkioverheid.nl/DomOrganisatieLatestCRL-G2.crl0
unknown
clean
https://gadgetswolf.com/
unknown
clean
http://www.diginotar.nl/cps/pkioverheid0
unknown
clean
https://gadgetswolf.com/post.php
unknown
clean
http://crt.comod
unknown
clean
https://govemedico.tk/
unknown
clean
https://homesoapmolds.com/post.php
unknown
clean
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
unknown
clean
http://www.hotmail.com/oe
unknown
clean
http://crl3.digicertP
unknown
clean
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
unknown
clean
http://crl.pkioverheid.nl/DomOvLatestCRL.crl0
unknown
clean
http://www.icra.org/vocabulary/.
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
http://investor.msn.com/
unknown
clean
http://www.%s.comPA
unknown
clean
https://gadgetswolf.com/post.phpi
unknown
clean
http://wmwifbajxxbcxmucxmlc.com/files/april24.dll~
unknown
clean
http://ocsp.entrust.net0D
unknown
clean
https://rnollg.com/kev/scfrd.dll$8
unknown
clean
https://secure.comodo.com/CPS0
unknown
clean
https://homesoapmolds.com/
unknown
clean
http://crl.entrust.net/2048ca.crl0
unknown
clean
https://gadgetswolf.com/post.php_
unknown
clean
https://govemedico.tk/post.php
unknown
clean
There are 25 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
homesoapmolds.com
104.21.60.169
clean
rnollg.com
172.67.150.228
clean
gadgetswolf.com
172.67.200.147
clean
govemedico.tk
104.21.73.69
clean

IPs

IP
Domain
Country
Active
Malicious
172.67.150.228
unknown
United States
unknown
clean
104.21.60.169
unknown
United States
unknown
clean
172.67.200.147
unknown
United States
unknown
clean
104.21.73.69
unknown
United States
unknown
clean

Registry

Path
Value
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
/!7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
MTTT
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ReviewToken
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EDC0D
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
VBAFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DefaultSheetR2L
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
UseSystemSeparators
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ThousandsSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DecimalSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EE36C
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EE734
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EE7D0
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
{E7E4BC40-E76A-11CE-A9BB-00AA004AE837} {000214E6-0000-0000-C000-000000000046} 0xFFFF
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
<07
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
@%SystemRoot%\system32\qagentrt.dll,-10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
@%SystemRoot%\System32\fveui.dll,-843
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
@%SystemRoot%\System32\fveui.dll,-844
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
@%SystemRoot%\System32\wuaueng.dll,-400
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F32F2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F3350
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 21
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
LastPurgeTime
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EXCELFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SavedLegacySettings
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F32F2
clean
C:\Windows\SysWOW64\msiexec.exe
ilyo
clean
C:\Windows\SysWOW64\msiexec.exe
ywizacy
clean
C:\Windows\SysWOW64\msiexec.exe
ywizacy
clean
C:\Windows\SysWOW64\msiexec.exe
ywizacy
clean
C:\Windows\SysWOW64\msiexec.exe
SavedLegacySettings
clean
There are 112 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
4CB000
heap default
page read and write
clean
F0000
unkown
page read and write
clean
2D4000
heap default
page read and write
clean
2B0000
heap default
page read and write
clean
700000
unkown
page readonly
clean
6B0000
unkown
page readonly
clean
27FE000
unkown
page read and write
clean
30C000
heap default
page read and write
clean
1B70000
unkown
page readonly
clean
28C000
unkown
page read and write
clean
180000
unkown
page execute and read and write
clean
1D10000
heap private
page read and write
clean
324000
heap default
page read and write
clean
2B7000
heap default
page read and write
clean
1D57000
unkown
page readonly
clean
487000
heap default
page read and write
clean
350000
heap default
page read and write
clean
850000
unkown
page readonly
clean
45B000
unkown
page read and write
clean
2B0000
unkown
page execute and read and write
clean
2137000
unkown
page readonly
clean
3AA000
unkown
page read and write
clean
470000
heap private
page read and write
clean
2F60000
unkown
page read and write
clean
23C0000
heap private
page read and write
clean
460000
unkown
page read and write
clean
8C000
unkown
page read and write
clean
240F000
unkown image
page read and write
clean
E0000
heap private
page read and write
clean
90000
unkown
page execute and read and write
clean
2D0C000
unkown
page read and write
clean
2A0000
unkown
page readonly
clean
23C9000
heap private
page read and write
clean
1F50000
unkown
page readonly
clean
120000
unkown
page read and write
clean
350000
heap default
page read and write
clean
7EFDF000
unkown
page read and write
clean
2426000
unkown image
page readonly
clean
308000
heap default
page read and write
clean
284E000
unkown
page read and write
clean
2EA000
heap default
page read and write
clean
2424000
unkown image
page read and write
clean
1D64000
unkown
page read and write
clean
140000
unkown
page read and write
clean
2330000
unkown image
page readonly
clean
460000
unkown
page read and write
clean
190000
unkown
page execute and read and write
clean
1ECE000
unkown
page read and write
clean
7EFDF000
unkown
page read and write
clean
3130000
heap private
page read and write
clean
530000
unkown
page readonly
clean
480000
unkown
page readonly
clean
3B0000
unkown
page readonly
clean
126000
unkown
page read and write
clean
160000
unkown
page readonly
clean
312000
heap default
page read and write
clean
2B61000
unkown
page read and write
clean
2900000
heap private
page read and write
clean
D0000
unkown
page read and write
clean
580000
unkown
page readonly
clean
18B000
unkown
page read and write
clean
2F50000
heap private
page read and write
clean
1F10000
unkown
page readonly
clean
29CE000
unkown
page read and write
clean
506000
heap private
page read and write
clean
2330000
unkown image
page readonly
clean
5D0000
unkown
page readonly
clean
36E000
heap default
page read and write
clean
2B1E000
unkown
page read and write
clean
2350000
unkown image
page readonly
clean
20000
unkown
page readonly
clean
23E7000
heap private
page read and write
clean
2A80000
unkown
page read and write
clean
60000
unkown
page readonly
clean
170000
unkown
page readonly
clean
4A4000
heap default
page read and write
clean
2352000
unkown image
page read and write
clean
24B0000
heap private
page read and write
clean
20000
unkown
page readonly
clean
B40000
heap private
page read and write
clean
2356000
unkown image
page execute read
clean
480000
heap default
page read and write
clean
1ED4000
heap private
page read and write
clean
D0000
unkown
page readonly
clean
1D4F000
unkown
page read and write
clean
2630000
heap private
page read and write
clean
1D20000
unkown
page read and write
clean
1FB0000
heap private
page read and write
clean
2330000
unkown image
page readonly
clean
39B000
unkown
page read and write
clean
950000
heap private
page read and write
clean
A80000
heap private
page read and write
clean
38E000
heap default
page read and write
clean
2355000
unkown image
page readonly
clean
357000
heap default
page read and write
clean
2330000
unkown image
page readonly
clean
23AE000
unkown
page read and write
clean
11C000
unkown
page read and write
clean
490000
heap private
page read and write
clean
1E0000
heap default
page read and write
clean
1D3D000
unkown
page read and write
clean
290000
unkown
page readonly
clean
500000
heap private
page read and write
clean
2410000
unkown image
page execute and read and write
clean
1ED0000
heap private
page read and write
clean
2331000
unkown image
page execute read
clean
1E8D000
unkown
page read and write
clean
2B70000
heap private
page read and write
clean
4B7000
heap default
page read and write
clean
4BD000
heap default
page read and write
clean
1D5F000
unkown
page read and write
clean
1EF2000
heap private
page read and write
clean
368000
heap default
page read and write
clean
2C5E000
unkown
page read and write
clean
2414000
unkown image
page read and write
clean
D0000
unkown
page write copy
clean
234F000
unkown
page read and write
clean
1B0000
heap default
page read and write
clean
2400000
unkown
page readonly
clean
1F0000
unkown
page read and write
clean
2330000
unkown image
page readonly
clean
29D0000
unkown
page readonly
clean
2400000
unkown image
page readonly
clean
4DD000
unkown
page read and write
clean
20000
unkown
page readonly
clean
2AD000
stack
page read and write
clean
2A71000
unkown
page read and write
clean
2EF000
heap default
page read and write
clean
36E000
unkown
page read and write
clean
E4000
heap private
page read and write
clean
39B000
heap default
page read and write
clean
319000
heap default
page read and write
clean
450000
unkown
page readonly
clean
2990000
unkown
page read and write
clean
There are 124 hidden memdumps, click here to show them.