IOCReport

loading gif

Files

File Path
Type
Category
Malicious
SecuriteInfo.com.Exploit.Siggen3.10350.14349.xls
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1251, Name of Creating Application: Microsoft Excel, Create Time/Date: Sat Sep 16 01:00:00 2006, Last Saved Time/Date: Fri Feb 19 10:48:36 2021, Security: 0
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4O403JZ\8[1].jjkes
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
downloaded
malicious
C:\Users\user\BASE.BABAA
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Microsoft Cabinet archive data, 59134 bytes, 1 file
dropped
clean
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
data
dropped
clean
C:\Users\user\AppData\Local\Temp\64CE0000
data
dropped
clean
C:\Users\user\AppData\Local\Temp\CabEABD.tmp
Microsoft Cabinet archive data, 59134 bytes, 1 file
dropped
clean
C:\Users\user\AppData\Local\Temp\TarEABE.tmp
data
modified
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Desktop.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Read-Only, Directory, ctime=Tue Oct 17 10:04:00 2017, mtime=Sat Feb 20 10:19:36 2021, atime=Sat Feb 20 10:19:36 2021, length=16384, window=hide
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\SecuriteInfo.com.Exploit.Siggen3.10350.14349.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Sat Feb 20 10:19:24 2021, mtime=Sat Feb 20 10:19:36 2021, atime=Sat Feb 20 10:19:36 2021, length=168448, window=hide
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\Desktop\57CE0000
Applesoft BASIC program data, first line number 16
dropped
clean
There are 2 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
malicious
C:\Windows\System32\rundll32.exe
rundll32 ..\BASE.BABAA,DllRegisterServer
malicious
C:\Windows\SysWOW64\rundll32.exe
rundll32 ..\BASE.BABAA,DllRegisterServer
malicious
C:\Windows\System32\wermgr.exe
C:\Windows\system32\wermgr.exe
malicious
C:\Windows\System32\wermgr.exe
C:\Windows\system32\wermgr.exe
malicious

URLs

Name
IP
Malicious
http://www.chipmania.it/mails/open.php
185.81.0.78
malicious
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
unknown
clean
http://www.windows.com/pctv.
unknown
clean
http://investor.msn.com
unknown
clean
http://www.msnbc.com/news/ticker.txt
unknown
clean
http://crl.pkioverheid.nl/DomOvLatestCRL.crl0
unknown
clean
http://www.icra.org/vocabulary/.
unknown
clean
https://194.5.249.156/rob60/651689_W617601.4E09BB1E4C0BB7F7B798E195EF9953B3/5/file/
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
http://crl.entrust.net/server1.crl0
unknown
clean
https://45.155.173.242/rob60/651689_W617601.4E09BB1E4C0BB7F7B798E195EF9953B3/5/file/
unknown
clean
http://ocsp.entrust.net03
unknown
clean
http://investor.msn.com/
unknown
clean
https://142.202.191.164/rob60/651689_W617601.4E09BB1E4C0BB7F7B798E195EF9953B3/5/file/
unknown
clean
http://crl.pkioverheid.nl/DomOrganisatieLatestCRL-G2.crl0
unknown
clean
http://www.%s.comPA
unknown
clean
http://www.diginotar.nl/cps/pkioverheid0
unknown
clean
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
unknown
clean
http://www.hotmail.com/oe
unknown
clean
http://ocsp.entrust.net0D
unknown
clean
https://secure.comodo.com/CPS0
unknown
clean
http://servername/isapibackend.dll
unknown
clean
http://crl.entrust.net/2048ca.crl0
unknown
clean
https://200.52.147.93/rob60/651689_W617601.4E09BB1E4C0BB7F7B798E195EF9953B3/5/file/
unknown
clean
There are 14 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
ident.me
176.58.123.25
clean
chipmania.it
185.81.0.78
clean
www.chipmania.it
unknown
clean

IPs

IP
Domain
Country
Active
Malicious
142.202.191.164
unknown
Reserved
unknown
malicious
45.155.173.242
unknown
Germany
unknown
malicious
200.52.147.93
unknown
Honduras
unknown
malicious
94.140.114.136
unknown
Latvia
unknown
malicious
185.81.0.78
unknown
Italy
unknown
clean
194.5.249.156
unknown
Romania
unknown
clean

Registry

Path
Value
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ll2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
MTTT
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ReviewToken
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EBEAD
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
VBAFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DefaultSheetR2L
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
UseSystemSeparators
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ThousandsSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DecimalSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EC284
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EC40A
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EC716
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EC793
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
{E7E4BC40-E76A-11CE-A9BB-00AA004AE837} {000214E6-0000-0000-C000-000000000046} 0xFFFF
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ix2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F3D9D
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F41D1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
LastPurgeTime
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EXCELFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SavedLegacySettings
clean
C:\Windows\System32\wermgr.exe
@%SystemRoot%\system32\qagentrt.dll,-10
clean
C:\Windows\System32\wermgr.exe
@%SystemRoot%\System32\fveui.dll,-843
clean
C:\Windows\System32\wermgr.exe
@%SystemRoot%\System32\fveui.dll,-844
clean
C:\Windows\System32\wermgr.exe
@%SystemRoot%\System32\wuaueng.dll,-400
clean
C:\Windows\System32\wermgr.exe
Blob
clean
C:\Windows\System32\wermgr.exe
Blob
clean
C:\Windows\System32\wermgr.exe
Blob
clean
C:\Windows\System32\wermgr.exe
Blob
clean
C:\Windows\System32\wermgr.exe
Blob
clean
C:\Windows\System32\wermgr.exe
Blob
clean
There are 105 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
684000
unkown
page read and write
malicious
684000
unkown
page read and write
malicious
650000
heap default
page read and write
malicious
8C8000
unkown
page read and write
malicious
290000
unkown
page execute and read and write
malicious
880000
unkown
page read and write
clean
32D41000
heap private
page read and write
clean
180000
unkown
page readonly
clean
341D0000
unkown
page readonly
clean
66C000
unkown
page read and write
clean
31A000
heap default
page read and write
clean
3A3000
unkown
page read and write
clean
1C0000
unkown
page read and write
clean
33F72000
unkown
page read and write
clean
E0000
unkown
page read and write
clean
690000
unkown
page read and write
clean
330000
heap private
page read and write
clean
33F4E000
unkown
page read and write
clean
384000
heap default
page read and write
clean
17C000
unkown
page read and write
clean
33F4E000
unkown
page read and write
clean
328000
heap default
page read and write
clean
2290000
heap private
page read and write
clean
690000
unkown
page read and write
clean
33F62000
unkown
page read and write
clean
33540000
heap private
page read and write
clean
5F0000
heap default
page read and write
clean
5A0000
unkown
page execute and read and write
clean
33F0F000
unkown
page read and write
clean
38B000
heap default
page read and write
clean
2294000
heap private
page read and write
clean
32E7C000
heap private
page read and write
clean
238C000
unkown
page read and write
clean
D0000
unkown
page readonly
clean
33F4D000
unkown
page read and write
clean
6E899000
unkown image
page readonly
clean
33EF1000
unkown
page read and write
clean
62D000
heap default
page read and write
clean
344D1000
unkown
page read and write
clean
10001000
unkown
page execute and read and write
clean
67A000
unkown
page read and write
clean
340B0000
heap private
page read and write
clean
2470000
heap private
page read and write
clean
651000
unkown
page read and write
clean
B2000
stack
page read and write
clean
1F77000
unkown
page readonly
clean
6E8D4000
unkown image
page readonly
clean
6E470000
unkown image
page readonly
clean
614000
heap default
page read and write
clean
CB000
unkown
page read and write
clean
627000
heap default
page read and write
clean
34513000
unkown
page read and write
clean
2180000
heap private
page read and write
clean
2D0000
heap private
page read and write
clean
590000
unkown
page readonly
clean
336AF000
unkown
page read and write
clean
1D97000
unkown
page readonly
clean
2B0000
heap default
page read and write
clean
316000
unkown
page read and write
clean
33F4E000
unkown
page read and write
clean
1D90000
unkown
page readonly
clean
33F54000
unkown
page read and write
clean
630000
unkown
page readonly
clean
38D000
heap default
page read and write
clean
2EE000
heap default
page read and write
clean
33F29000
unkown
page read and write
clean
333B0000
heap private
page read and write
clean
6B1000
unkown
page read and write
clean
2B7000
heap default
page read and write
clean
33490000
heap private
page read and write
clean
651000
unkown
page read and write
clean
22D0000
heap private
page read and write
clean
D0000
unkown
page read and write
clean
32A000
unkown
page read and write
clean
33F49000
unkown
page read and write
clean
7D0000
unkown
page readonly
clean
33F4C000
unkown
page read and write
clean
382000
heap default
page read and write
clean
310000
heap default
page read and write
clean
1B0000
unkown
page readonly
clean
33F26000
unkown
page read and write
clean
6E471000
unkown image
page execute read
clean
33EF0000
unkown
page read and write
clean
484000
heap private
page read and write
clean
1E8F000
unkown
page read and write
clean
67A000
unkown
page read and write
clean
E0000
unkown
page execute and read and write
clean
690000
unkown
page read and write
clean
190000
unkown
page execute and read and write
clean
690000
unkown
page read and write
clean
7EFDF000
unkown
page read and write
clean
1BB0000
unkown
page readonly
clean
390000
heap default
page read and write
clean
333B5000
heap private
page read and write
clean
33F98000
unkown
page read and write
clean
1E0000
heap default
page read and write
clean
33F65000
unkown
page read and write
clean
4B0000
unkown
page readonly
clean
410000
unkown
page readonly
clean
32B43000
heap private
page read and write
clean
340000
unkown
page execute and read and write
clean
480000
heap private
page read and write
clean
344D0000
unkown
page read and write
clean
1B0000
unkown
page readonly
clean
22B2000
heap private
page read and write
clean
160000
unkown
page readonly
clean
651000
unkown
page read and write
clean
6B0000
unkown
page read and write
clean
5F7000
heap default
page read and write
clean
21E000
heap default
page read and write
clean
20000
unkown
page readonly
clean
651000
unkown
page read and write
clean
1D0000
unkown
page read and write
clean
344F5000
unkown
page read and write
clean
6B2000
unkown
page read and write
clean
33F62000
unkown
page read and write
clean
110000
unkown
page readonly
clean
33F49000
unkown
page read and write
clean
60000
unkown
page readonly
clean
1E7000
heap default
page read and write
clean
33F4E000
unkown
page read and write
clean
274000
heap private
page read and write
clean
3B0000
unkown
page read and write
clean
33CF7000
unkown
page readonly
clean
2150000
heap private
page read and write
clean
203D000
unkown
page read and write
clean
333EB000
heap private
page read and write
clean
6E8BC000
unkown image
page readonly
clean
344F5000
unkown
page read and write
clean
33F26000
unkown
page read and write
clean
33F4E000
unkown
page read and write
clean
610000
unkown
page readonly
clean
1D0000
unkown
page read and write
clean
6E8BA000
unkown image
page read and write
clean
32E41000
heap private
page read and write
clean
32E90000
unkown
page readonly
clean
33270000
unkown
page readonly
clean
20000
unkown
page read and write
clean
140000
unkown
page read and write
clean
490000
unkown
page readonly
clean
344D1000
unkown
page read and write
clean
2E0000
unkown
page execute and read and write
clean
3E6000
unkown
page read and write
clean
31C000
unkown
page read and write
clean
3326C000
unkown
page read and write
clean
270000
heap private
page read and write
clean
1EE0000
heap private
page read and write
clean
33720000
unkown
page readonly
clean
39F000
heap default
page read and write
clean
334A3000
heap private
page read and write
clean
6E470000
unkown image
page readonly
clean
6B2000
unkown
page read and write
clean
2E0000
unkown
page read and write
clean
20000
unkown
page readonly
clean
33F4E000
unkown
page read and write
clean
32E40000
heap private
page read and write
clean
1AB000
unkown
page read and write
clean
3406F000
unkown
page read and write
clean
2256000
stack
page read and write
clean
2040000
unkown
page write copy
clean
1C50000
heap private
page read and write
clean
65E000
unkown
page read and write
clean
32E46000
heap private
page read and write
clean
651000
unkown
page read and write
clean
33B10000
unkown
page readonly
clean
33F4E000
unkown
page read and write
clean
1DBF000
unkown
page read and write
clean
There are 157 hidden memdumps, click here to show them.