IOCReport

loading gif

Files

File Path
Type
Category
Malicious
91476525608-04012021.xlsm
Microsoft Excel 2007+
initial sample
malicious
C:\Users\user\Desktop\~$91476525608-04012021.xlsm
data
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\F5AD18CF.gif
GIF image data, version 89a, 1600 x 1600
dropped
clean
C:\Users\user\AppData\Local\Temp\7FCE0000
data
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\91476525608-04012021.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Wed Aug 26 14:08:15 2020, mtime=Fri Apr 2 03:53:38 2021, atime=Fri Apr 2 03:53:38 2021, length=177712, window=hide
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Desktop.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Read-Only, Directory, ctime=Tue Oct 17 10:04:00 2017, mtime=Fri Apr 2 03:53:38 2021, atime=Fri Apr 2 03:53:38 2021, length=8192, window=hide
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\Desktop\20DE0000
data
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\170F9197-F193-4F05-B2F8-6C4BDA897C38
XML 1.0 document, UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\457FCD63.gif
GIF image data, version 89a, 1600 x 1600
dropped
clean
C:\Users\user\AppData\Local\Temp\C1C10000
data
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\UProof\CUSTOM.DIC
Little-endian UTF-16 Unicode text, with CR line terminators
dropped
clean
C:\Users\user\Desktop\72C10000
data
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\FB206F33.gif
GIF image data, version 89a, 1600 x 1600
dropped
clean
C:\Users\user\AppData\Local\Temp\98DE0000
data
dropped
clean
C:\Users\user\Desktop\59DE0000
data
dropped
clean
There are 6 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
malicious
C:\Windows\System32\rundll32.exe
rundll32 ..\Hodas.vyur,PluginInit
malicious
C:\Windows\System32\rundll32.exe
rundll32 ..\Hodas.vyur1,PluginInit
malicious
C:\Windows\System32\rundll32.exe
rundll32 ..\Hodas.vyur2,PluginInit
malicious
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding
malicious
C:\Windows\SysWOW64\rundll32.exe
rundll32 ..\Hodas.vyur,PluginInit
malicious
C:\Windows\SysWOW64\rundll32.exe
rundll32 ..\Hodas.vyur1,PluginInit
malicious
C:\Windows\SysWOW64\rundll32.exe
rundll32 ..\Hodas.vyur2,PluginInit
malicious

URLs

Name
IP
Malicious
http://195.123.210.186/44285,5327891204.dat
195.123.210.186
malicious
http://91.211.89.28/44285,5327891204.dat
91.211.89.28
malicious
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
unknown
clean
http://www.windows.com/pctv.
unknown
clean
http://investor.msn.com
unknown
clean
http://www.msnbc.com/news/ticker.txt
unknown
clean
http://www.icra.org/vocabulary/.
unknown
clean
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
unknown
clean
http://www.hotmail.com/oe
unknown
clean
http://45.150.67.243/44285,5327891204.dat
45.150.67.243
clean
http://investor.msn.com/
unknown
clean
https://api.diagnosticssdf.office.com
unknown
clean
https://login.microsoftonline.com/
unknown
clean
https://shell.suite.office.com:1443
unknown
clean
https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorize
unknown
clean
https://autodiscover-s.outlook.com/
unknown
clean
https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Flickr
unknown
clean
https://cdn.entity.
unknown
clean
https://api.addins.omex.office.net/appinfo/query
unknown
clean
https://clients.config.office.net/user/v1.0/tenantassociationkey
unknown
clean
https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/
unknown
clean
https://powerlift.acompli.net
unknown
clean
https://rpsticket.partnerservices.getmicrosoftkey.com
unknown
clean
https://lookup.onenote.com/lookup/geolocation/v1
unknown
clean
https://cortana.ai
unknown
clean
https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
unknown
clean
https://cloudfiles.onenote.com/upload.aspx
unknown
clean
https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
unknown
clean
https://entitlement.diagnosticssdf.office.com
unknown
clean
https://na01.oscs.protection.outlook.com/api/SafeLinksApi/GetPolicy
unknown
clean
https://api.aadrm.com/
unknown
clean
https://ofcrecsvcapi-int.azurewebsites.net/
unknown
clean
https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPolicies
unknown
clean
https://api.microsoftstream.com/api/
unknown
clean
https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=Immersive
unknown
clean
https://cr.office.com
unknown
clean
https://portal.office.com/account/?ref=ClientMeControl
unknown
clean
https://ecs.office.com/config/v2/Office
unknown
clean
https://graph.ppe.windows.net
unknown
clean
https://res.getmicrosoftkey.com/api/redemptionevents
unknown
clean
https://powerlift-frontdesk.acompli.net
unknown
clean
https://tasks.office.com
unknown
clean
https://officeci.azurewebsites.net/api/
unknown
clean
https://sr.outlook.office.net/ws/speech/recognize/assistant/work
unknown
clean
https://store.office.cn/addinstemplate
unknown
clean
https://outlook.office.com/autosuggest/api/v1/init?cvid=
unknown
clean
https://globaldisco.crm.dynamics.com
unknown
clean
https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
unknown
clean
https://store.officeppe.com/addinstemplate
unknown
clean
https://dev0-api.acompli.net/autodetect
unknown
clean
https://www.odwebp.svc.ms
unknown
clean
https://api.powerbi.com/v1.0/myorg/groups
unknown
clean
https://web.microsoftstream.com/video/
unknown
clean
https://graph.windows.net
unknown
clean
https://dataservice.o365filtering.com/
unknown
clean
https://officesetup.getmicrosoftkey.com
unknown
clean
https://analysis.windows.net/powerbi/api
unknown
clean
https://prod-global-autodetect.acompli.net/autodetect
unknown
clean
https://outlook.office365.com/autodiscover/autodiscover.json
unknown
clean
https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-ios
unknown
clean
https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
unknown
clean
https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.json
unknown
clean
https://ncus.contentsync.
unknown
clean
https://onedrive.live.com/about/download/?windows10SyncClientInstalled=false
unknown
clean
https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/
unknown
clean
http://weather.service.msn.com/data.aspx
unknown
clean
https://apis.live.net/v5.0/
unknown
clean
https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asks
unknown
clean
https://word.uservoice.com/forums/304948-word-for-ipad-iphone-ios
unknown
clean
https://autodiscover-s.outlook.com/autodiscover/autodiscover.xml
unknown
clean
https://management.azure.com
unknown
clean
https://wus2.contentsync.
unknown
clean
https://incidents.diagnostics.office.com
unknown
clean
https://clients.config.office.net/user/v1.0/ios
unknown
clean
https://insertmedia.bing.office.net/odc/insertmedia
unknown
clean
https://o365auditrealtimeingestion.manage.office.com
unknown
clean
https://outlook.office365.com/api/v1.0/me/Activities
unknown
clean
https://api.office.net
unknown
clean
https://incidents.diagnosticssdf.office.com
unknown
clean
https://asgsmsproxyapi.azurewebsites.net/
unknown
clean
https://clients.config.office.net/user/v1.0/android/policies
unknown
clean
https://entitlement.diagnostics.office.com
unknown
clean
https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.json
unknown
clean
https://outlook.office.com/
unknown
clean
https://storage.live.com/clientlogs/uploadlocation
unknown
clean
https://templatelogging.office.com/client/log
unknown
clean
https://outlook.office365.com/
unknown
clean
https://webshell.suite.office.com
unknown
clean
https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=OneDrive
unknown
clean
https://management.azure.com/
unknown
clean
https://login.windows.net/common/oauth2/authorize
unknown
clean
https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile
unknown
clean
https://graph.windows.net/
unknown
clean
https://api.powerbi.com/beta/myorg/imports
unknown
clean
https://devnull.onenote.com
unknown
clean
https://ncus.pagecontentsync.
unknown
clean
https://r4.res.office365.com/footprintconfig/v1.7/scripts/fpconfig.json
unknown
clean
https://messaging.office.com/
unknown
clean
https://dataservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
unknown
clean
https://augloop.office.com/v2
unknown
clean
https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Bing
unknown
clean
https://skyapi.live.net/Activity/
unknown
clean
https://clients.config.office.net/user/v1.0/mac
unknown
clean
https://dataservice.o365filtering.com
unknown
clean
https://api.cortana.ai
unknown
clean
https://onedrive.live.com
unknown
clean
https://ovisualuiapp.azurewebsites.net/pbiagave/
unknown
clean
https://visio.uservoice.com/forums/368202-visio-on-devices
unknown
clean
There are 98 hidden URLs, click here to show them.

IPs

IP
Domain
Country
Malicious
195.123.210.186
unknown
Bulgaria
clean
45.150.67.243
unknown
Montenegro
clean
91.211.89.28
unknown
Ukraine
clean

Registry

Path
Value
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
(~4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
MTTT
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
VBAFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ReviewToken
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EC9F4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DefaultSheetR2L
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
UseSystemSeparators
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ThousandsSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DecimalSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ECD3E
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ECE76
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ECF31
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ECFEC
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ED069
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
{E7E4BC40-E76A-11CE-A9BB-00AA004AE837} {000214E6-0000-0000-C000-000000000046} 0xFFFF
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
e(4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F4E9D
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F50A0
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
LastPurgeTime
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EXCELFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SavedLegacySettings
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
cb6
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
rb6
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
RemoteClearDate
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
Last
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
FilePath
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
StartDate
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
EndDate
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
Properties
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
Url
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
LastClean
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
DisableWinHttpCertAuth
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
DisableIsOwnerRegex
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
DisableSessionAwareHttpClose
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
DisableADALForExtendedApps
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
DisableADALSetSilentAuth
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
msoridDisableGuestCredProvider
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
msoridDisableOstringReplace
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
LastBootTime
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
VBAFiles
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
MSForms
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
MSComctlLib
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
ReviewToken
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
1B90B
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
1
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
UpdateComplete
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
DefaultSheetR2L
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
UseSystemSeparators
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
ThousandsSeparator
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
DecimalSeparator
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
1BF25
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
1C03F
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
1C148
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
1C204
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
1C2B0
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
;s6
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
2A530
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
2A6F5
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
ProductFiles
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
en-US
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
en-US
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
EXCELFiles
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
RoamingConfigurableSettings
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
RoamingLastSyncTime
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
RoamingLastWriteTime
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
CacheReady
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
LastRequest
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
CacheReady
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
LastUpdate
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
NextUpdate
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
ProductFiles
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
ProductFiles
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
ProductFiles
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
ProductFiles
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
LastBootTime
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
LastPurgeTime
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
r23
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ED29B
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ED672
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ED75C
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ED826
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ED920
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ED9AC
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
w>3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F581F
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F5A8F
clean
There are 170 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
2702000
unkown
page readonly
clean
1E37000
unkown
page readonly
clean
1D97000
unkown
page readonly
clean
67F000
unkown
page read and write
clean
27A5000
unkown
page readonly
clean
27C2000
unkown
page readonly
clean
27D2000
unkown
page readonly
clean
5F4000
heap private
page read and write
clean
2702000
unkown
page readonly
clean
D0000
unkown
page read and write
clean
20A5000
heap private
page read and write
clean
2502000
unkown
page readonly
clean
2796000
unkown
page readonly
clean
400000
heap private
page read and write
clean
28E5000
unkown
page readonly
clean
2775000
unkown
page readonly
clean
2942000
unkown
page readonly
clean
2B75000
heap private
page read and write
clean
2160000
unkown
page readonly
clean
2C80000
unkown
page readonly
clean
70000
unkown
page read and write
clean
2912000
unkown
page readonly
clean
2B85000
heap private
page read and write
clean
51F000
unkown
page read and write
clean
2935000
unkown
page readonly
clean
27E9000
unkown
page readonly
clean
28A9000
unkown
page readonly
clean
2885000
unkown
page readonly
clean
11D000
unkown
page read and write
clean
2F50000
unkown
page read and write
clean
2972000
unkown
page readonly
clean
2120000
heap private
page read and write
clean
2849000
unkown
page readonly
clean
1B7000
heap default
page read and write
clean
27A2000
unkown
page readonly
clean
2BA0000
unkown
page readonly
clean
28A2000
unkown
page readonly
clean
770000
unkown
page readonly
clean
2866000
unkown
page readonly
clean
60000
unkown
page read and write
clean
2B6000
unkown
page read and write
clean
60000
unkown
page readonly
clean
410000
unkown
page readonly
clean
2A70000
unkown
page readonly
clean
27ED000
unkown
page readonly
clean
2772000
unkown
page readonly
clean
2855000
unkown
page readonly
clean
2872000
unkown
page readonly
clean
430000
unkown
page read and write
clean
2704000
unkown
page readonly
clean
2826000
unkown
page readonly
clean
2B02000
unkown
page readonly
clean
2815000
unkown
page readonly
clean
2842000
unkown
page readonly
clean
26E4000
unkown
page readonly
clean
27F6000
unkown
page readonly
clean
26C4000
unkown
page readonly
clean
2065000
heap private
page read and write
clean
2B80000
unkown
page readonly
clean
2744000
unkown
page readonly
clean
2839000
unkown
page readonly
clean
2A90000
unkown
page readonly
clean
480000
heap private
page read and write
clean
3B0000
unkown
page write copy
clean
280000
unkown
page read and write
clean
2842000
unkown
page readonly
clean
2745000
unkown
page readonly
clean
2EC0000
unkown
page read and write
clean
21F9000
heap private
page read and write
clean
1BB0000
unkown
page readonly
clean
1B0000
heap default
page read and write
clean
2885000
unkown
page readonly
clean
2879000
unkown
page readonly
clean
2949000
unkown
page readonly
clean
2A32000
unkown
page readonly
clean
28D2000
unkown
page readonly
clean
87000
heap default
page read and write
clean
33D000
heap default
page read and write
clean
27D2000
unkown
page readonly
clean
2704000
unkown
page readonly
clean
337000
heap default
page read and write
clean
2069000
heap private
page read and write
clean
20000
unkown
page readonly
clean
210000
unkown
page readonly
clean
211B000
heap private
page read and write
clean
160000
unkown
page read and write
clean
1F20000
heap private
page read and write
clean
20E0000
heap private
page read and write
clean
21C0000
unkown
page readonly
clean
2B70000
heap private
page read and write
clean
21F0000
heap private
page read and write
clean
E0000
unkown
page read and write
clean
2E6000
unkown
page read and write
clean
28A2000
unkown
page readonly
clean
2A50000
unkown
page readonly
clean
1C50000
unkown
page readonly
clean
2BF0000
unkown
page readonly
clean
28C5000
unkown
page readonly
clean
2895000
unkown
page readonly
clean
20E0000
heap private
page read and write
clean
28F6000
unkown
page readonly
clean
76E000
unkown
page read and write
clean
2732000
unkown
page readonly
clean
20E5000
heap private
page read and write
clean
2548000
unkown
page readonly
clean
300000
heap default
page read and write
clean
60000
unkown
page readonly
clean
5F0000
heap private
page read and write
clean
2542000
unkown
page readonly
clean
2712000
unkown
page readonly
clean
2872000
unkown
page readonly
clean
1FA0000
unkown
page write copy
clean
21F5000
heap private
page read and write
clean
2B0000
unkown
page read and write
clean
2A30000
unkown
page readonly
clean
2756000
unkown
page readonly
clean
2742000
unkown
page readonly
clean
590000
unkown
page readonly
clean
2979000
unkown
page readonly
clean
27D5000
unkown
page readonly
clean
27D4000
unkown
page readonly
clean
282D000
unkown
page readonly
clean
1D17000
unkown
page readonly
clean
6B0000
unkown
page readonly
clean
2A70000
unkown
page readonly
clean
1EE000
heap default
page read and write
clean
2896000
unkown
page readonly
clean
26C2000
unkown
page readonly
clean
2508000
unkown
page readonly
clean
28FD000
unkown
page readonly
clean
2832000
unkown
page readonly
clean
2869000
unkown
page readonly
clean
15B000
unkown
page read and write
clean
36E000
heap default
page read and write
clean
530000
unkown
page readonly
clean
2809000
unkown
page readonly
clean
2792000
unkown
page readonly
clean
2862000
unkown
page readonly
clean
1B30000
unkown
page readonly
clean
1C6000
unkown
page read and write
clean
27F2000
unkown
page readonly
clean
610000
unkown
page readonly
clean
20A0000
heap private
page read and write
clean
2B40000
unkown
page readonly
clean
260000
unkown
page write copy
clean
34B000
heap default
page read and write
clean
254000
heap private
page read and write
clean
330000
heap default
page read and write
clean
2812000
unkown
page readonly
clean
20000
unkown
page readonly
clean
484000
heap private
page read and write
clean
2724000
unkown
page readonly
clean
80000
heap default
page read and write
clean
2270000
unkown
page readonly
clean
27B5000
unkown
page readonly
clean
BEF000
unkown
page read and write
clean
2180000
unkown
page readonly
clean
2855000
unkown
page readonly
clean
2814000
unkown
page readonly
clean
21A0000
unkown
page readonly
clean
2B60000
unkown
page readonly
clean
2A90000
unkown
page readonly
clean
2829000
unkown
page readonly
clean
20000
unkown
page readonly
clean
2786000
unkown
page readonly
clean
2965000
unkown
page readonly
clean
28F9000
unkown
page readonly
clean
2602000
unkown
page readonly
clean
1F90000
unkown
page readonly
clean
2919000
unkown
page readonly
clean
2BAB000
heap private
page read and write
clean
2642000
unkown
page readonly
clean
190000
unkown
page read and write
clean
29F2000
unkown
page readonly
clean
20A9000
heap private
page read and write
clean
20B000
unkown
page read and write
clean
490000
unkown
page readonly
clean
2AB0000
unkown
page readonly
clean
2802000
unkown
page readonly
clean
2802000
unkown
page readonly
clean
2C00000
unkown
page readonly
clean
2865000
unkown
page readonly
clean
2722000
unkown
page readonly
clean
2ED0000
unkown
page read and write
clean
2BBB000
heap private
page read and write
clean
27E5000
unkown
page readonly
clean
BE000
heap default
page read and write
clean
28C6000
unkown
page readonly
clean
28B5000
unkown
page readonly
clean
D0000
unkown
page read and write
clean
466000
unkown
page read and write
clean
2762000
unkown
page readonly
clean
307000
heap default
page read and write
clean
2060000
heap private
page read and write
clean
1AB000
unkown
page read and write
clean
26E2000
unkown
page readonly
clean
346000
heap default
page read and write
clean
2618000
unkown
page readonly
clean
27F4000
unkown
page readonly
clean
27E6000
unkown
page readonly
clean
2785000
unkown
page readonly
clean
2290000
unkown
page readonly
clean
2B80000
heap private
page read and write
clean
27B6000
unkown
page readonly
clean
2612000
unkown
page readonly
clean
2825000
unkown
page readonly
clean
404000
heap private
page read and write
clean
120000
unkown
page readonly
clean
27C6000
unkown
page readonly
clean
250000
heap private
page read and write
clean
2995000
unkown
page readonly
clean
There are 201 hidden memdumps, click here to show them.