IOCReport

loading gif

Files

File Path
Type
Category
Malicious
TRA-St-0015-O01.xlsx
CDFV2 Encrypted
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\kinsvc[1].exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
downloaded
malicious
C:\Users\user\AppData\Local\Temp\tmp2222.tmp
XML 1.0 document, ASCII text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Roaming\XaHKwnPuj.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Users\user\Desktop\~$TRA-St-0015-O01.xlsx
data
dropped
malicious
C:\Users\Public\vbc.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
modified
malicious
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Microsoft Cabinet archive data, 59134 bytes, 1 file
dropped
clean
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E0F5C59F9FA661F6F4C50B87FEF3A15A
data
dropped
clean
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
data
dropped
clean
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E0F5C59F9FA661F6F4C50B87FEF3A15A
data
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\284D8619.jpeg
gd-jpeg v1.0 (using IJG JPEG v80), quality = 90", baseline, precision 8, 700x990, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\BADF7393.emf
Windows Enhanced Metafile (EMF) image data version 0x10000
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\CEC07078.jpeg
gd-jpeg v1.0 (using IJG JPEG v80), quality = 90", baseline, precision 8, 700x990, frames 3
dropped
clean
C:\Users\user\AppData\Local\Temp\CabA5C2.tmp
Microsoft Cabinet archive data, 59134 bytes, 1 file
dropped
clean
C:\Users\user\AppData\Local\Temp\TarA5C3.tmp
data
dropped
clean
There are 5 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
'C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE' -Embedding
malicious
C:\Users\Public\vbc.exe
'C:\Users\Public\vbc.exe'
malicious
C:\Windows\System32\schtasks.exe
'C:\Windows\System32\schtasks.exe' /Create /TN 'Updates\XaHKwnPuj' /XML 'C:\Users\user\AppData\Local\Temp\tmp2222.tmp'
malicious
C:\Users\Public\vbc.exe
C:\Users\Public\vbc.exe
malicious
C:\Users\Public\vbc.exe
C:\Users\Public\vbc.exe
malicious
C:\Users\Public\vbc.exe
C:\Users\Public\vbc.exe
malicious
C:\Users\Public\vbc.exe
C:\Users\Public\vbc.exe
malicious
C:\Users\Public\vbc.exe
C:\Users\Public\vbc.exe
malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
clean

URLs

Name
IP
Malicious
http://www.%s.comPA
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
http://www.day.com/dam/1.0
unknown
clean
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
unknown
clean

Domains

Name
IP
Malicious
spicesherbs.in
162.241.148.128
clean

IPs

IP
Domain
Country
Active
Malicious
162.241.148.128
unknown
United States
unknown
clean

Registry

Path
Value
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
d|6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
MTTT
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ReviewToken
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EF4CA
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
VBAFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DefaultSheetR2L
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
UseSystemSeparators
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ThousandsSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DecimalSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
7c6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F3BD8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F4EDB
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 21
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
LastPurgeTime
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EXCELFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F3BD8
clean
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
EquationEditorFilesIntl_1033
clean
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
SavedLegacySettings
clean
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
Blob
clean
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
Blob
clean
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
Blob
clean
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
Blob
clean
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
Blob
clean
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
Blob
clean
There are 56 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
12381000
unkown
page read and write
malicious
23DE000
unkown
page read and write
malicious
C6E000
unkown image
page readonly
clean
1ED000
heap default
page read and write
clean
4E0000
unkown
page read and write
clean
7FE8AC60000
unkown
page execute and read and write
clean
4D9000
unkown
page read and write
clean
C6E000
unkown image
page readonly
clean
9F0000
unkown
page readonly
clean
1A970000
unkown
page readonly
clean
5A0000
unkown
page read and write
clean
510000
unkown
page read and write
clean
1A820000
unkown
page read and write
clean
BF2000
unkown image
page execute read
clean
1B710000
unkown
page read and write
clean
3F0000
unkown
page read and write
clean
1A840000
unkown
page read and write
clean
230000
unkown
page readonly
clean
1B05F000
unkown
page read and write
clean
1237D000
unkown
page read and write
clean
BF0000
unkown image
page readonly
clean
1AC80000
unkown
page read and write
clean
410000
unkown
page read and write
clean
1B89A000
unkown
page read and write
clean
21A000
heap default
page read and write
clean
4CB000
unkown
page read and write
clean
BF0000
unkown image
page readonly
clean
4D2000
unkown
page read and write
clean
7FE8AB50000
unkown
page read and write
clean
1A782000
unkown
page read and write
clean
3F0000
heap private
page read and write
clean
50E000
unkown
page read and write
clean
1ACF0000
unkown
page read and write
clean
1B2A0000
heap private
page execute and read and write
clean
4C0000
unkown
page read and write
clean
BF0000
unkown image
page readonly
clean
444000
heap private
page read and write
clean
4C0000
unkown
page read and write
clean
1A84C000
unkown
page read and write
clean
12371000
unkown
page read and write
clean
1A7F0000
unkown
page read and write
clean
1A84E000
unkown
page read and write
clean
1B180000
unkown
page read and write
clean
1AED4000
unkown
page read and write
clean
4C2000
unkown
page read and write
clean
1AD20000
unkown
page read and write
clean
BF2000
unkown image
page execute read
clean
1A830000
unkown
page read and write
clean
1A7E0000
unkown
page read and write
clean
4F4000
heap private
page read and write
clean
1AC7A000
unkown
page read and write
clean
1B691000
unkown
page read and write
clean
BF0000
unkown image
page readonly
clean
5D6000
unkown
page read and write
clean
41F000
unkown
page read and write
clean
1AD7B000
heap private
page read and write
clean
1B0000
heap default
page read and write
clean
1B600000
unkown
page read and write
clean
432000
unkown
page read and write
clean
1B600000
unkown
page read and write
clean
222000
heap default
page read and write
clean
4DE000
unkown
page read and write
clean
3E0000
unkown
page read and write
clean
1ACC0000
unkown
page read and write
clean
BF2000
unkown image
page execute read
clean
1AD00000
heap private
page read and write
clean
1AD20000
unkown
page read and write
clean
7FE8AB43000
unkown
page read and write
clean
4D0000
unkown
page readonly
clean
2190000
unkown
page readonly
clean
1B17D000
unkown
page read and write
clean
C6E000
unkown image
page readonly
clean
4C0000
unkown
page read and write
clean
BF2000
unkown image
page execute read
clean
43B000
unkown
page read and write
clean
1B600000
unkown
page read and write
clean
236F000
unkown
page read and write
clean
1BA40000
unkown
page readonly
clean
1A7AD000
unkown
page read and write
clean
1A840000
unkown
page read and write
clean
1B7000
heap default
page read and write
clean
1A7AD000
unkown
page read and write
clean
510000
unkown
page read and write
clean
3D0000
unkown
page readonly
clean
224000
heap default
page read and write
clean
1AD10000
unkown
page read and write
clean
BF0000
unkown image
page readonly
clean
820000
unkown
page readonly
clean
430000
unkown
page read and write
clean
4D0000
unkown
page read and write
clean
7FE8AC16000
unkown
page execute and read and write
clean
430000
unkown
page read and write
clean
4D0000
unkown
page read and write
clean
BF2000
unkown image
page execute read
clean
BF0000
unkown image
page readonly
clean
1B6E0000
unkown
page read and write
clean
9D2000
unkown
page read and write
clean
C6E000
unkown image
page readonly
clean
1AC70000
unkown
page read and write
clean
1C70F000
unkown
page read and write
clean
7FE8ACB1000
unkown
page read and write
clean
1AEE0000
unkown
page read and write
clean
4C0000
unkown
page read and write
clean
4C0000
unkown
page read and write
clean
1A850000
unkown
page read and write
clean
C6E000
unkown image
page readonly
clean
3A0000
unkown
page read and write
clean
BF0000
unkown image
page readonly
clean
4C2000
unkown
page read and write
clean
1B6D0000
unkown
page read and write
clean
4C0000
unkown
page read and write
clean
1A704000
unkown
page read and write
clean
21C000
heap default
page read and write
clean
BF2000
unkown image
page execute read
clean
4D0000
unkown
page read and write
clean
1B83D000
unkown
page read and write
clean
4D5000
unkown
page read and write
clean
1B841000
unkown
page read and write
clean
1AD10000
unkown
page read and write
clean
1A778000
unkown
page read and write
clean
7FFFFF00000
unkown
page execute and read and write
clean
9C0000
unkown
page read and write
clean
510000
unkown
page read and write
clean
4D0000
unkown
page read and write
clean
A90000
unkown
page read and write
clean
20000
unkown
page read and write
clean
190000
unkown
page read and write
clean
1A781000
unkown
page read and write
clean
1A96C000
unkown
page read and write
clean
4C0000
unkown
page read and write
clean
12378000
unkown
page read and write
clean
4D0000
unkown
page read and write
clean
1A850000
unkown
page read and write
clean
BF0000
unkown image
page readonly
clean
1ACB0000
unkown
page read and write
clean
4C0000
unkown
page read and write
clean
1A800000
unkown
page readonly
clean
1ACD0000
unkown
page read and write
clean
C6E000
unkown image
page readonly
clean
165000
unkown
page read and write
clean
1A7B0000
unkown
page read and write
clean
4C0000
unkown
page read and write
clean
3C0000
unkown
page read and write
clean
9D0000
unkown
page readonly
clean
1AC90000
unkown
page read and write
clean
C6E000
unkown image
page readonly
clean
1AD45000
heap private
page read and write
clean
4C2000
unkown
page read and write
clean
BF2000
unkown image
page execute read
clean
4D5000
unkown
page read and write
clean
1AEF0000
unkown
page read and write
clean
520000
heap private
page execute and read and write
clean
9E0000
unkown
page read and write
clean
7FE8ABE0000
unkown
page read and write
clean
1B320000
unkown
page readonly
clean
1AC50000
unkown
page read and write
clean
271C000
unkown
page read and write
clean
400000
unkown
page read and write
clean
1B6B0000
unkown
page read and write
clean
1ACF0000
unkown
page read and write
clean
4D0000
unkown
page read and write
clean
500000
unkown
page read and write
clean
7FE8AC50000
unkown
page read and write
clean
1AED1000
unkown
page read and write
clean
7FE8AC59000
unkown
page read and write
clean
1A850000
unkown
page read and write
clean
7FE8ABF0000
unkown
page execute and read and write
clean
4E0000
unkown
page read and write
clean
4E5000
unkown
page read and write
clean
4C0000
unkown
page read and write
clean
BF0000
unkown image
page readonly
clean
500000
unkown
page read and write
clean
1C33F000
unkown
page read and write
clean
4C0000
unkown
page read and write
clean
4C0000
unkown
page read and write
clean
6A0000
unkown
page readonly
clean
1A860000
unkown
page read and write
clean
4C0000
unkown
page read and write
clean
500000
unkown
page read and write
clean
4E0000
unkown
page read and write
clean
1B6C0000
unkown
page read and write
clean
1ACEC000
unkown
page read and write
clean
1B700000
unkown
page read and write
clean
9C0000
unkown
page read and write
clean
BF0000
unkown image
page readonly
clean
1A840000
unkown
page read and write
clean
4E7000
unkown
page read and write
clean
4D0000
unkown
page read and write
clean
4CB000
unkown
page read and write
clean
BF2000
unkown image
page execute read
clean
4E0000
unkown
page read and write
clean
BF0000
unkown image
page readonly
clean
BF0000
unkown image
page readonly
clean
4E0000
unkown
page read and write
clean
1A74E000
unkown
page read and write
clean
7FE8AB34000
unkown
page read and write
clean
4F0000
heap private
page read and write
clean
BF0000
unkown image
page readonly
clean
3D0000
unkown
page read and write
clean
1AC40000
unkown
page readonly
clean
BF0000
unkown image
page readonly
clean
7FE8AB4D000
unkown
page execute and read and write
clean
4C0000
unkown
page read and write
clean
1ACD0000
unkown
page read and write
clean
450000
unkown
page readonly
clean
BF0000
unkown image
page readonly
clean
1C53F000
unkown
page read and write
clean
1BF5F000
unkown
page read and write
clean
1B840000
unkown
page read and write
clean
BF0000
unkown image
page readonly
clean
1AF00000
unkown
page read and write
clean
BF2000
unkown image
page execute read
clean
1AD30000
unkown
page read and write
clean
4C7000
unkown
page read and write
clean
BF2000
unkown image
page execute read
clean
1A79E000
unkown
page read and write
clean
2A0000
unkown
page read and write
clean
4C0000
unkown
page read and write
clean
1ACC0000
unkown
page read and write
clean
4C2000
unkown
page read and write
clean
BF2000
unkown image
page execute read
clean
7FE8ABEC000
unkown
page execute and read and write
clean
1AC61000
unkown
page read and write
clean
1B6A0000
unkown
page read and write
clean
1B627000
unkown
page read and write
clean
1AEC0000
unkown
page read and write
clean
1ACE0000
unkown
page read and write
clean
C6E000
unkown image
page readonly
clean
1B6F0000
unkown
page read and write
clean
2D6000
unkown
page read and write
clean
9F0000
unkown
page read and write
clean
4D6000
unkown
page read and write
clean
C6E000
unkown image
page readonly
clean
1ACA0000
unkown
page read and write
clean
9E0000
unkown
page read and write
clean
1AD04000
heap private
page read and write
clean
B90000
unkown
page read and write
clean
4C0000
unkown
page read and write
clean
1AD40000
heap private
page read and write
clean
9E0000
unkown
page read and write
clean
437000
unkown
page read and write
clean
4CE000
unkown
page read and write
clean
1ADF6000
unkown
page read and write
clean
B00000
unkown
page read and write
clean
4C0000
unkown
page read and write
clean
4D0000
unkown
page read and write
clean
1AC40000
unkown
page read and write
clean
4C0000
unkown
page read and write
clean
3C2000
unkown
page read and write
clean
1A800000
unkown
page read and write
clean
BF2000
unkown image
page execute read
clean
430000
unkown
page read and write
clean
C6E000
unkown image
page readonly
clean
1ACB0000
unkown
page read and write
clean
430000
unkown
page read and write
clean
500000
unkown
page read and write
clean
3E0000
unkown
page read and write
clean
9CB000
unkown
page read and write
clean
C6E000
unkown image
page readonly
clean
1AEE0000
unkown
page read and write
clean
1A860000
unkown
page read and write
clean
4D0000
unkown
page read and write
clean
1AF30000
unkown
page read and write
clean
420000
unkown
page read and write
clean
1ACE0000
unkown
page read and write
clean
7FE8AB3D000
unkown
page execute and read and write
clean
2371000
unkown
page read and write
clean
7FE8AB40000
unkown
page read and write
clean
1B600000
unkown
page read and write
clean
4D0000
unkown
page read and write
clean
1ADC0000
unkown
page read and write
clean
41A000
unkown
page read and write
clean
4E0000
unkown
page read and write
clean
1AEC0000
unkown
page read and write
clean
BF0000
unkown image
page readonly
clean
9D0000
unkown
page read and write
clean
4D0000
unkown
page read and write
clean
1A79E000
unkown
page read and write
clean
4EE000
unkown
page read and write
clean
4D0000
unkown
page read and write
clean
504000
unkown
page read and write
clean
7FE8ACA0000
unkown
page read and write
clean
B10000
heap private
page read and write
clean
C6E000
unkown image
page readonly
clean
4C0000
unkown
page read and write
clean
BF0000
unkown image
page readonly
clean
7FE8ABE6000
unkown
page read and write
clean
1A760000
unkown
page read and write
clean
1C70E000
unkown
page read and write | page guard
clean
1C12F000
unkown
page read and write
clean
440000
heap private
page read and write
clean
7FE8AB8C000
unkown
page execute and read and write
clean
B00000
unkown
page readonly
clean
A00000
unkown
page read and write
clean
7FE8AB5D000
unkown
page execute and read and write
clean
1A810000
unkown
page read and write
clean
A10000
heap private
page execute and read and write
clean
There are 287 hidden memdumps, click here to show them.