IOCReport

loading gif

Files

File Path
Type
Category
Malicious
Marine Tiger.xlsm
Microsoft Excel 2007+
initial sample
malicious
C:\Users\user\Desktop\~$Marine Tiger.xlsm
data
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\E0EFE241-5146-4D5E-B9A0-B1624BA1283F
XML 1.0 document, UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
malicious
C:\Windows\System32\cmd.exe
'C:\Windows\System32\cmd.exe' /c schtasks /run /tn \Microsoft\Windows\DiskCleanup\SilentCleanup /I
malicious
C:\Windows\System32\schtasks.exe
schtasks /run /tn \Microsoft\Windows\DiskCleanup\SilentCleanup /I
malicious
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding
malicious
C:\Windows\SysWOW64\cmd.exe
'C:\Windows\System32\cmd.exe' /c schtasks /run /tn \Microsoft\Windows\DiskCleanup\SilentCleanup /I
malicious
C:\Windows\SysWOW64\schtasks.exe
schtasks /run /tn \Microsoft\Windows\DiskCleanup\SilentCleanup /I
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
clean

URLs

Name
IP
Malicious
https://api.diagnosticssdf.office.com
unknown
clean
https://login.microsoftonline.com/
unknown
clean
https://shell.suite.office.com:1443
unknown
clean
https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorize
unknown
clean
https://autodiscover-s.outlook.com/
unknown
clean
https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Flickr
unknown
clean
https://cdn.entity.
unknown
clean
https://api.addins.omex.office.net/appinfo/query
unknown
clean
https://wus2-000.contentsync.
unknown
clean
https://clients.config.office.net/user/v1.0/tenantassociationkey
unknown
clean
https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/
unknown
clean
https://powerlift.acompli.net
unknown
clean
https://rpsticket.partnerservices.getmicrosoftkey.com
unknown
clean
https://lookup.onenote.com/lookup/geolocation/v1
unknown
clean
https://cortana.ai
unknown
clean
https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
unknown
clean
https://cloudfiles.onenote.com/upload.aspx
unknown
clean
https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
unknown
clean
https://entitlement.diagnosticssdf.office.com
unknown
clean
https://na01.oscs.protection.outlook.com/api/SafeLinksApi/GetPolicy
unknown
clean
https://api.aadrm.com/
unknown
clean
https://ofcrecsvcapi-int.azurewebsites.net/
unknown
clean
https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPolicies
unknown
clean
https://api.microsoftstream.com/api/
unknown
clean
https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=Immersive
unknown
clean
https://cr.office.com
unknown
clean
https://portal.office.com/account/?ref=ClientMeControl
unknown
clean
https://ecs.office.com/config/v2/Office
unknown
clean
https://graph.ppe.windows.net
unknown
clean
https://res.getmicrosoftkey.com/api/redemptionevents
unknown
clean
https://powerlift-frontdesk.acompli.net
unknown
clean
https://tasks.office.com
unknown
clean
https://officeci.azurewebsites.net/api/
unknown
clean
https://sr.outlook.office.net/ws/speech/recognize/assistant/work
unknown
clean
https://store.office.cn/addinstemplate
unknown
clean
https://wus2-000.pagecontentsync.
unknown
clean
https://outlook.office.com/autosuggest/api/v1/init?cvid=
unknown
clean
https://globaldisco.crm.dynamics.com
unknown
clean
https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
unknown
clean
https://store.officeppe.com/addinstemplate
unknown
clean
https://dev0-api.acompli.net/autodetect
unknown
clean
https://www.odwebp.svc.ms
unknown
clean
https://api.powerbi.com/v1.0/myorg/groups
unknown
clean
https://web.microsoftstream.com/video/
unknown
clean
https://graph.windows.net
unknown
clean
https://dataservice.o365filtering.com/
unknown
clean
https://officesetup.getmicrosoftkey.com
unknown
clean
https://analysis.windows.net/powerbi/api
unknown
clean
https://prod-global-autodetect.acompli.net/autodetect
unknown
clean
https://outlook.office365.com/autodiscover/autodiscover.json
unknown
clean
https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-ios
unknown
clean
https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
unknown
clean
https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.json
unknown
clean
https://onedrive.live.com/about/download/?windows10SyncClientInstalled=false
unknown
clean
https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/
unknown
clean
http://weather.service.msn.com/data.aspx
unknown
clean
https://apis.live.net/v5.0/
unknown
clean
https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asks
unknown
clean
https://word.uservoice.com/forums/304948-word-for-ipad-iphone-ios
unknown
clean
https://autodiscover-s.outlook.com/autodiscover/autodiscover.xml
unknown
clean
https://management.azure.com
unknown
clean
https://incidents.diagnostics.office.com
unknown
clean
https://clients.config.office.net/user/v1.0/ios
unknown
clean
https://insertmedia.bing.office.net/odc/insertmedia
unknown
clean
https://o365auditrealtimeingestion.manage.office.com
unknown
clean
https://outlook.office365.com/api/v1.0/me/Activities
unknown
clean
https://api.office.net
unknown
clean
https://incidents.diagnosticssdf.office.com
unknown
clean
https://asgsmsproxyapi.azurewebsites.net/
unknown
clean
https://clients.config.office.net/user/v1.0/android/policies
unknown
clean
https://entitlement.diagnostics.office.com
unknown
clean
https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.json
unknown
clean
https://outlook.office.com/
unknown
clean
https://storage.live.com/clientlogs/uploadlocation
unknown
clean
https://templatelogging.office.com/client/log
unknown
clean
https://outlook.office365.com/
unknown
clean
https://webshell.suite.office.com
unknown
clean
https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=OneDrive
unknown
clean
https://management.azure.com/
unknown
clean
https://ncus-000.contentsync.
unknown
clean
https://login.windows.net/common/oauth2/authorize
unknown
clean
https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile
unknown
clean
https://graph.windows.net/
unknown
clean
https://api.powerbi.com/beta/myorg/imports
unknown
clean
https://devnull.onenote.com
unknown
clean
https://r4.res.office365.com/footprintconfig/v1.7/scripts/fpconfig.json
unknown
clean
https://messaging.office.com/
unknown
clean
https://dataservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
unknown
clean
https://augloop.office.com/v2
unknown
clean
https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Bing
unknown
clean
https://skyapi.live.net/Activity/
unknown
clean
https://clients.config.office.net/user/v1.0/mac
unknown
clean
https://dataservice.o365filtering.com
unknown
clean
https://api.cortana.ai
unknown
clean
https://onedrive.live.com
unknown
clean
https://ovisualuiapp.azurewebsites.net/pbiagave/
unknown
clean
https://visio.uservoice.com/forums/368202-visio-on-devices
unknown
clean
https://directory.services.
unknown
clean
https://login.windows-ppe.net/common/oauth2/authorize
unknown
clean
https://staging.cortana.ai
unknown
clean
There are 90 hidden URLs, click here to show them.

Registry

Path
Value
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
s 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
MTTT
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
VBAFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ReviewToken
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ECF60
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
windir
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DefaultSheetR2L
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
UseSystemSeparators
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ThousandsSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DecimalSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
LastPurgeTime
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EXCELFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
o/1
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
p/1
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
RemoteClearDate
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
Last
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
FilePath
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
StartDate
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
EndDate
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
Properties
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
Url
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
LastClean
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
DisableWinHttpCertAuth
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
DisableIsOwnerRegex
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
DisableSessionAwareHttpClose
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
DisableADALForExtendedApps
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
DisableADALSetSilentAuth
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
msoridDisableGuestCredProvider
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
msoridDisableOstringReplace
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
LastBootTime
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
VBAFiles
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
MSForms
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
MSComctlLib
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
ReviewToken
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
199FA
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
ProductFiles
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
en-US
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
en-US
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
EXCELFiles
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
RoamingConfigurableSettings
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
RoamingLastSyncTime
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
RoamingLastWriteTime
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
LastBootTime
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
CacheReady
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
LastRequest
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
CacheReady
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
LastUpdate
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
NextUpdate
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
ProductFiles
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
ProductFiles
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
ProductFiles
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
ProductFiles
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
LastPurgeTime
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
(*3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ED0E6
clean
There are 73 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
3B4000
heap private
page read and write
clean
C0E000
unkown
page read and write
clean
620000
unkown
page readonly
clean
3F7000
heap default
page read and write
clean
42D000
heap default
page read and write
clean
A0F000
unkown
page read and write
clean
3F0000
heap default
page read and write
clean
24D000
unkown
page read and write
clean
438000
heap default
page read and write
clean
3B0000
heap private
page read and write
clean
106000
unkown
page read and write
clean
35E000
unkown
page read and write
clean
D0000
unkown
page read and write
clean
60000
unkown
page readonly
clean
436000
heap default
page read and write
clean
AAE000
unkown
page read and write
clean
There are 6 hidden memdumps, click here to show them.