IOCReport

loading gif

Files

File Path
Type
Category
Malicious
Signature.xlsx
CDFV2 Encrypted
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\hm1[1].exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
downloaded
malicious
C:\Users\Public\vbc.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\3B65EA87.jpeg
gd-jpeg v1.0 (using IJG JPEG v80), quality = 90", baseline, precision 8, 700x990, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\86CDB2DC.jpeg
gd-jpeg v1.0 (using IJG JPEG v80), quality = 90", baseline, precision 8, 700x990, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\E74B891E.emf
Windows Enhanced Metafile (EMF) image data version 0x10000
dropped
clean
C:\Users\user\Desktop\~$Signature.xlsx
data
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
'C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE' -Embedding
malicious
C:\Users\Public\vbc.exe
'C:\Users\Public\vbc.exe'
malicious
C:\Users\Public\vbc.exe
C:\Users\Public\vbc.exe
malicious
C:\Users\Public\vbc.exe
C:\Users\Public\vbc.exe
malicious
C:\Users\Public\vbc.exe
C:\Users\Public\vbc.exe
malicious
C:\Users\Public\vbc.exe
C:\Users\Public\vbc.exe
malicious
C:\Users\Public\vbc.exe
C:\Users\Public\vbc.exe
malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
clean

URLs

Name
IP
Malicious
http://18.194.54.219/wows/hm1.exe
18.194.54.219
malicious
http://thesnake.herokuapp.com/snakes
unknown
clean
http://www.day.com/dam/1.0
unknown
clean
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
unknown
clean

IPs

IP
Domain
Country
Active
Malicious
18.194.54.219
unknown
United States
unknown
malicious

Registry

Path
Value
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
;!6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
MTTT
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ReviewToken
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F08D7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
VBAFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DefaultSheetR2L
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
UseSystemSeparators
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ThousandsSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DecimalSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
u'6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F4F97
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F5699
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 21
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
LastPurgeTime
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EXCELFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F4F97
clean
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
EquationEditorFilesIntl_1033
clean
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
SavedLegacySettings
clean
There are 50 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
20D1000
unkown
page read and write
malicious
30D9000
unkown
page read and write
malicious
48F0000
unkown
page readonly
clean
1E0000
unkown
page read and write
clean
1E60000
unkown
page read and write
clean
53AE000
stack
page read and write
clean
51FE000
unkown
page read and write
clean
1FC0000
unkown
page read and write
clean
4610000
unkown
page read and write
clean
212000
unkown image
page execute read
clean
700000
heap private
page read and write
clean
690000
unkown
page read and write
clean
4140000
unkown
page read and write
clean
58EE000
stack
page read and write
clean
433D000
stack
page read and write
clean
6EE000
unkown
page read and write
clean
485C000
unkown
page read and write
clean
6F0000
unkown
page read and write
clean
2AE000
unkown image
page readonly
clean
2AE000
unkown image
page readonly
clean
561F000
unkown
page read and write
clean
210000
unkown image
page readonly
clean
41C0000
unkown
page read and write
clean
690000
unkown
page read and write
clean
1E60000
unkown
page read and write
clean
4EA0000
heap private
page execute and read and write
clean
690000
unkown
page read and write
clean
4CA0000
heap private
page read and write
clean
229A000
unkown
page read and write
clean
6A0000
unkown
page read and write
clean
710000
unkown
page readonly
clean
300000
unkown
page read and write
clean
210000
unkown image
page readonly
clean
2AE000
unkown image
page readonly
clean
20CE000
unkown
page read and write | page guard
clean
1E70000
unkown
page read and write
clean
212000
unkown image
page execute read
clean
212000
unkown image
page execute read
clean
212000
unkown image
page execute read
clean
210000
unkown image
page readonly
clean
20CF000
unkown
page read and write
clean
212000
unkown image
page execute read
clean
41F0000
unkown
page read and write
clean
53B1000
unkown
page read and write
clean
3B0000
unkown
page read and write
clean
414F000
unkown
page read and write
clean
6F0000
unkown
page read and write
clean
212000
unkown image
page execute read
clean
2AE000
unkown image
page readonly
clean
48B0000
heap private
page read and write
clean
40D6000
unkown
page read and write
clean
212000
unkown image
page execute read
clean
210000
unkown image
page readonly
clean
212000
unkown image
page execute read
clean
48D2000
heap private
page read and write
clean
3E7000
heap default
page read and write
clean
1E60000
unkown
page read and write
clean
6F0000
unkown
page read and write
clean
4B8F000
stack
page read and write
clean
1F80000
heap private
page execute and read and write
clean
4EE0000
unkown
page readonly
clean
561E000
unkown
page read and write | page guard
clean
2AE000
unkown image
page readonly
clean
600000
unkown
page read and write
clean
2AE000
unkown image
page readonly
clean
210000
unkown image
page readonly
clean
689000
heap private
page read and write
clean
4C80000
heap private
page read and write
clean
210000
unkown image
page readonly
clean
4CB0000
unkown
page read and write
clean
1F70000
unkown
page read and write
clean
47DF000
stack
page read and write
clean
4CCD000
unkown
page read and write
clean
41D0000
unkown
page read and write
clean
210000
unkown image
page readonly
clean
210000
unkown image
page readonly
clean
210000
unkown image
page readonly
clean
4A1E000
unkown
page read and write
clean
1E70000
unkown
page read and write
clean
210000
unkown image
page readonly
clean
2CA000
unkown
page execute and read and write
clean
48B4000
heap private
page read and write
clean
1F3000
unkown
page execute and read and write
clean
200000
unkown
page read and write
clean
4BDE000
unkown
page read and write
clean
4340000
unkown
page readonly
clean
212000
unkown image
page execute read
clean
4150000
unkown
page read and write
clean
178000
stack
page read and write
clean
210000
unkown image
page readonly
clean
42C000
heap default
page read and write
clean
210000
unkown image
page readonly
clean
2AE000
unkown image
page readonly
clean
890000
unkown
page readonly
clean
2D7000
unkown
page execute and read and write
clean
41E0000
unkown
page read and write
clean
5C0000
heap private
page execute and read and write
clean
310000
heap default
page read and write
clean
550000
unkown
page readonly
clean
2C7000
unkown
page execute and read and write
clean
2AE000
unkown image
page readonly
clean
1E80000
heap private
page read and write
clean
5C2E000
stack
page read and write
clean
4170000
unkown
page read and write
clean
40F0000
unkown
page read and write
clean
20D000
unkown
page execute and read and write
clean
4670000
unkown
page read and write
clean
306000
unkown
page read and write
clean
6F0000
unkown
page read and write
clean
6F0000
unkown
page read and write
clean
413C000
unkown
page read and write
clean
1F4000
unkown
page read and write
clean
40E0000
unkown
page read and write
clean
1F6A000
unkown
page read and write
clean
20000
unkown
page read and write
clean
2AE000
unkown image
page readonly
clean
420000
heap default
page read and write
clean
210000
unkown image
page readonly
clean
489000
unkown
page read and write
clean
3E0000
heap default
page read and write
clean
210000
unkown image
page readonly
clean
48B000
heap default
page read and write
clean
4160000
unkown
page read and write
clean
3D0000
unkown
page read and write
clean
5404000
unkown
page read and write
clean
2AE000
unkown image
page readonly
clean
41BE000
unkown
page read and write
clean
3A0000
unkown
page execute and read and write
clean
2DB000
unkown
page execute and read and write
clean
2AE000
unkown image
page readonly
clean
2AE000
unkown image
page readonly
clean
7EFDF000
unkown
page read and write
clean
1FD000
unkown
page execute and read and write
clean
212000
unkown image
page execute read
clean
30D1000
unkown
page read and write
clean
3D0000
unkown
page read and write
clean
210000
unkown image
page readonly
clean
680000
heap private
page read and write
clean
1DA000
unkown
page read and write
clean
210000
unkown image
page readonly
clean
491000
unkown
page read and write
clean
404000
heap default
page read and write
clean
53B0000
unkown
page read and write
clean
210000
unkown image
page readonly
clean
1F60000
unkown
page read and write
clean
4E0000
unkown
page readonly
clean
212000
unkown image
page execute read
clean
4A8E000
unkown
page read and write
clean
2D2000
unkown
page read and write
clean
212000
unkown image
page execute read
clean
423E000
unkown
page read and write
clean
210000
unkown image
page readonly
clean
3C0000
unkown
page readonly
clean
5A7E000
stack
page read and write
clean
There are 144 hidden memdumps, click here to show them.