IOCReport

loading gif

Files

File Path
Type
Category
Malicious
SecuriteInfo.com.Heur.30497.xls
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1251, Author: , Last Saved By: , Name of Creating Application: Microsoft Excel, Last Printed: Tue Jan 26 16:17:13 2021, Create Time/Date: Thu Apr 23 13:26:24 2020, Last Saved Time/Date: Tue Jan 26 16:28:15 2021, Security: 0
initial sample
malicious
C:\ProgramData\formnet.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4O403JZ\scfrd[1].dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
downloaded
malicious
C:\Users\user\AppData\Local\Temp\FFDE0000
data
dropped
clean
C:\Users\user\AppData\Roaming\Ida\suicy.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Desktop.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Read-Only, Directory, ctime=Tue Oct 17 10:04:00 2017, mtime=Wed Jan 27 11:09:42 2021, atime=Wed Jan 27 11:09:42 2021, length=8192, window=hide
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\SecuriteInfo.com.Heur.30497.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Wed Jan 27 11:09:32 2021, mtime=Wed Jan 27 11:09:42 2021, atime=Wed Jan 27 11:09:42 2021, length=99328, window=hide
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
ASCII text, with CRLF line terminators
modified
clean
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\03IOIHRV.txt
ASCII text
downloaded
clean
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\0RM1C1X2.txt
ASCII text
downloaded
clean
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\HPDR9FYI.txt
ASCII text
downloaded
clean
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\SZU335ZX.txt
ASCII text
downloaded
clean
C:\Users\user\Desktop\D0EE0000
Applesoft BASIC program data, first line number 16
dropped
clean
There are 3 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
malicious
C:\Windows\System32\rundll32.exe
'C:\Windows\System32\rundll32.exe' C:\ProgramData\formnet.dll,DllRegisterServer
malicious
C:\Windows\SysWOW64\rundll32.exe
'C:\Windows\System32\rundll32.exe' C:\ProgramData\formnet.dll,DllRegisterServer
malicious
C:\Windows\SysWOW64\msiexec.exe
msiexec.exe
clean

URLs

Name
IP
Malicious
https://rnollg.com/kev/scfrd.dll
unknown
malicious
http://wmwifbajxxbcxmucxmlc.com/files/april24.dll)
unknown
clean
http://www.windows.com/pctv.
unknown
clean
http://investor.msn.com
unknown
clean
http://www.msnbc.com/news/ticker.txt
unknown
clean
https://govemedico.tk/t
unknown
clean
http://crl.entrust.net/server1.crl0
unknown
clean
http://crl3.digicert
unknown
clean
http://ocsp.entrust.net03
unknown
clean
https://homesoapmolds.com/post.phpx
unknown
clean
http://crl.pkioverheid.nl/DomOrganisatieLatestCRL-G2.crl0
unknown
clean
https://gadgetswolf.com/
unknown
clean
http://www.diginotar.nl/cps/pkioverheid0
unknown
clean
https://gadgetswolf.com/post.php
unknown
clean
https://govemedico.tk/
unknown
clean
https://homesoapmolds.com/post.php
unknown
clean
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
unknown
clean
http://www.hotmail.com/oe
unknown
clean
https://gadgetswolf.com/post.phpF/
unknown
clean
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
unknown
clean
http://crl.pkioverheid.nl/DomOvLatestCRL.crl0
unknown
clean
http://www.icra.org/vocabulary/.
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
http://investor.msn.com/
unknown
clean
http://www.%s.comPA
unknown
clean
http://wmwifbajxxbcxmucxmlc.com/files/april24.dll~
unknown
clean
http://ocsp.entrust.net0D
unknown
clean
https://rnollg.com/kev/scfrd.dll$8
unknown
clean
https://secure.comodo.com/CPS0
unknown
clean
https://homesoapmolds.com/
unknown
clean
http://crl.entrust.net/2048ca.crl0
unknown
clean
Https://homesoapmolds.com/post.php
unknown
clean
https://govemedico.tk/post.php
unknown
clean
There are 23 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
homesoapmolds.com
172.67.198.109
clean
rnollg.com
172.67.150.228
clean
gadgetswolf.com
172.67.200.147
clean
govemedico.tk
172.67.158.184
clean

IPs

IP
Domain
Country
Active
Malicious
172.67.158.184
unknown
United States
unknown
clean
172.67.150.228
unknown
United States
unknown
clean
172.67.200.147
unknown
United States
unknown
clean
172.67.198.109
unknown
United States
unknown
clean

Registry

Path
Value
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
9z6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
MTTT
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ReviewToken
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ED604
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
VBAFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DefaultSheetR2L
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
UseSystemSeparators
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ThousandsSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DecimalSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EDCF7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EE08F
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EE12B
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
{E7E4BC40-E76A-11CE-A9BB-00AA004AE837} {000214E6-0000-0000-C000-000000000046} 0xFFFF
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
7i6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
@%SystemRoot%\system32\qagentrt.dll,-10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
@%SystemRoot%\System32\fveui.dll,-843
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
@%SystemRoot%\System32\fveui.dll,-844
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
@%SystemRoot%\System32\wuaueng.dll,-400
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F2B35
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F2B83
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 21
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
LastPurgeTime
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EXCELFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SavedLegacySettings
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Blob
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F2B35
clean
C:\Windows\SysWOW64\msiexec.exe
ilyo
clean
C:\Windows\SysWOW64\msiexec.exe
obizypb
clean
C:\Windows\SysWOW64\msiexec.exe
obizypb
clean
C:\Windows\SysWOW64\msiexec.exe
obizypb
clean
C:\Windows\SysWOW64\msiexec.exe
SavedLegacySettings
clean
There are 112 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
25C000
unkown
page read and write
clean
350000
unkown
page read and write
clean
1A0000
unkown
page read and write
clean
6D4000
heap default
page read and write
clean
414000
heap private
page read and write
clean
360000
unkown
page readonly
clean
350000
unkown
page read and write
clean
2A61000
unkown
page read and write
clean
A64000
unkown image
page read and write
clean
930000
unkown
page readonly
clean
970000
unkown image
page readonly
clean
22C0000
unkown
page read and write
clean
59E000
unkown
page read and write
clean
190000
unkown
page write copy
clean
60000
unkown
page read and write
clean
2BFD000
unkown
page read and write
clean
2460000
heap private
page read and write
clean
770000
heap default
page read and write
clean
500000
unkown
page readonly
clean
20000
unkown
page readonly
clean
708000
heap default
page read and write
clean
6DB000
heap default
page read and write
clean
90000
unkown
page readonly
clean
20B000
unkown
page read and write
clean
A54000
unkown image
page read and write
clean
7EFDF000
unkown
page read and write
clean
2980000
unkown
page readonly
clean
2117000
unkown
page readonly
clean
43F000
unkown
page read and write
clean
6EA000
heap default
page read and write
clean
686000
heap private
page read and write
clean
3050000
heap private
page read and write
clean
70000
unkown
page read and write
clean
1ED0000
unkown
page readonly
clean
2E0000
heap private
page read and write
clean
33E000
unkown
page read and write
clean
1B40000
unkown
page readonly
clean
2B0E000
unkown
page read and write
clean
2B8E000
unkown
page read and write
clean
690000
heap default
page read and write
clean
680000
unkown
page readonly
clean
480000
heap default
page read and write
clean
A4F000
unkown image
page read and write
clean
2F6000
unkown
page read and write
clean
697000
heap default
page read and write
clean
238D000
unkown
page read and write
clean
6EF000
heap default
page read and write
clean
AD0000
unkown
page readonly
clean
5A0000
unkown
page readonly
clean
A66000
unkown image
page readonly
clean
2D2C000
unkown
page read and write
clean
150000
heap default
page read and write
clean
D0000
unkown
page read and write
clean
11C000
unkown
page read and write
clean
5F0000
heap private
page read and write
clean
960000
heap private
page read and write
clean
970000
unkown image
page readonly
clean
23A1000
unkown
page read and write
clean
380000
heap default
page read and write
clean
20000
heap private
page read and write
clean
420000
unkown
page readonly
clean
285E000
unkown
page read and write
clean
130000
unkown
page readonly
clean
18E000
heap default
page read and write
clean
157000
heap default
page read and write
clean
27EA000
unkown
page read and write
clean
A50000
unkown image
page execute and read and write
clean
7B0000
unkown
page readonly
clean
713000
heap default
page read and write
clean
6CD000
heap default
page read and write
clean
971000
unkown image
page execute read
clean
250000
heap private
page read and write
clean
140000
unkown
page execute and read and write
clean
90000
unkown
page readonly
clean
1F30000
unkown
page readonly
clean
290000
heap private
page read and write
clean
6B4000
heap default
page read and write
clean
2040000
heap private
page read and write
clean
2EC0000
unkown
page read and write
clean
120000
unkown
page readonly
clean
1B0000
heap private
page read and write
clean
2880000
heap private
page read and write
clean
23FE000
unkown
page read and write
clean
2D30000
unkown
page read and write
clean
2ED000
stack
page read and write
clean
717000
heap default
page read and write
clean
2469000
heap private
page read and write
clean
380000
heap private
page read and write
clean
2980000
unkown
page read and write
clean
970000
unkown image
page readonly
clean
992000
unkown image
page read and write
clean
2C5E000
unkown
page read and write
clean
2C0000
unkown
page read and write
clean
2487000
heap private
page read and write
clean
1D27000
unkown
page readonly
clean
100000
unkown
page read and write
clean
400000
unkown
page read and write
clean
24F000
unkown
page read and write
clean
7EFDF000
unkown
page read and write
clean
294000
heap private
page read and write
clean
995000
unkown image
page readonly
clean
150000
unkown
page execute and read and write
clean
680000
heap private
page read and write
clean
6B7000
heap default
page read and write
clean
772000
unkown
page read and write
clean
732000
heap default
page read and write
clean
120000
unkown
page readonly
clean
2EB0000
heap private
page read and write
clean
71B000
heap default
page read and write
clean
A40000
unkown image
page readonly
clean
24A0000
unkown
page readonly
clean
90000
unkown
page execute and read and write
clean
410000
heap private
page read and write
clean
41D000
unkown
page read and write
clean
2F0000
unkown
page execute and read and write
clean
970000
unkown image
page readonly
clean
996000
unkown image
page execute read
clean
230E000
unkown
page read and write
clean
2460000
heap private
page read and write
clean
234E000
unkown
page read and write
clean
42F000
unkown
page read and write
clean
990000
unkown image
page readonly
clean
2B2000
heap private
page read and write
clean
444000
unkown
page read and write
clean
6C7000
heap default
page read and write
clean
250000
unkown
page readonly
clean
340000
unkown
page readonly
clean
20000
unkown
page readonly
clean
76F000
unkown
page read and write
clean
410000
heap private
page read and write
clean
970000
unkown image
page readonly
clean
6B0000
heap default
page read and write
clean
13C000
unkown
page read and write
clean
There are 123 hidden memdumps, click here to show them.