IOCReport

loading gif

Files

File Path
Type
Category
Malicious
Contract_132508562.xlsm
Microsoft Excel 2007+
initial sample
malicious
C:\Users\user\Desktop\~$Contract_132508562.xlsm
data
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\46F474E4.gif
GIF image data, version 89a, 1600 x 1600
dropped
clean
C:\Users\user\AppData\Local\Temp\A4DE0000
data
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Contract_132508562.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Wed Aug 26 14:08:15 2020, mtime=Tue Apr 6 19:55:39 2021, atime=Tue Apr 6 19:55:39 2021, length=181141, window=hide
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Desktop.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Read-Only, Directory, ctime=Tue Oct 17 10:04:00 2017, mtime=Tue Apr 6 19:55:39 2021, atime=Tue Apr 6 19:55:39 2021, length=8192, window=hide
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\Desktop\55DE0000
data
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
malicious
C:\Windows\System32\rundll32.exe
rundll32 ..\Hodas.vyur,PluginInit
malicious
C:\Windows\System32\rundll32.exe
rundll32 ..\Hodas.vyur1,PluginInit
malicious
C:\Windows\System32\rundll32.exe
rundll32 ..\Hodas.vyur2,PluginInit
malicious

URLs

Name
IP
Malicious
http://185.212.131.194/44285,5327891204.dat
185.212.131.194
malicious
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
unknown
clean
http://www.windows.com/pctv.
unknown
clean
http://investor.msn.com
unknown
clean
http://www.msnbc.com/news/ticker.txt
unknown
clean
http://www.icra.org/vocabulary/.
unknown
clean
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
unknown
clean
http://www.hotmail.com/oe
unknown
clean
http://investor.msn.com/
unknown
clean

IPs

IP
Domain
Country
Malicious
83.136.232.110
unknown
Russian Federation
clean
190.14.37.247
unknown
Panama
clean
185.212.131.194
unknown
Germany
clean

Registry

Path
Value
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
rh8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
MTTT
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
VBAFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ReviewToken
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ECFDD
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DefaultSheetR2L
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
UseSystemSeparators
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ThousandsSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DecimalSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ED2F8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ED3B4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ED45F
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ED52A
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ED5A7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
{E7E4BC40-E76A-11CE-A9BB-00AA004AE837} {000214E6-0000-0000-C000-000000000046} 0xFFFF
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
#r8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
LastPurgeTime
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
109B27
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
109CFB
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EXCELFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SavedLegacySettings
clean
There are 96 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
2946000
unkown
page readonly
clean
2DA0000
unkown
page readonly
clean
2B19000
unkown
page readonly
clean
2916000
unkown
page readonly
clean
2CD2000
unkown
page readonly
clean
6D0000
unkown
page readonly
clean
2852000
unkown
page readonly
clean
29C2000
unkown
page readonly
clean
2B05000
unkown
page readonly
clean
28E6000
unkown
page readonly
clean
22F0000
unkown
page readonly
clean
E0000
unkown
page read and write
clean
2F0000
heap private
page read and write
clean
2762000
unkown
page readonly
clean
2440000
unkown
page readonly
clean
260000
unkown
page readonly
clean
29A4000
unkown
page readonly
clean
190000
heap default
page read and write
clean
2A36000
unkown
page readonly
clean
20000
unkown
page readonly
clean
22E0000
unkown
page readonly
clean
29C4000
unkown
page readonly
clean
28E2000
unkown
page readonly
clean
29E5000
unkown
page readonly
clean
2C40000
heap private
page read and write
clean
2698000
unkown
page readonly
clean
2935000
unkown
page readonly
clean
2A66000
unkown
page readonly
clean
2999000
unkown
page readonly
clean
336000
unkown
page read and write
clean
28B6000
unkown
page readonly
clean
16D000
heap default
page read and write
clean
2B35000
unkown
page readonly
clean
2B65000
unkown
page readonly
clean
216000
unkown
page read and write
clean
28F2000
unkown
page readonly
clean
2B12000
unkown
page readonly
clean
2D70000
unkown
page readonly
clean
2844000
unkown
page readonly
clean
29F9000
unkown
page readonly
clean
2B42000
unkown
page readonly
clean
25C000
unkown
page read and write
clean
2842000
unkown
page readonly
clean
2B82000
unkown
page readonly
clean
1F40000
unkown
page write copy
clean
23C5000
heap private
page read and write
clean
22C0000
unkown
page read and write
clean
29C2000
unkown
page readonly
clean
130000
heap default
page read and write
clean
2992000
unkown
page readonly
clean
430000
unkown
page write copy
clean
390000
unkown
page write copy
clean
297D000
unkown
page readonly
clean
2892000
unkown
page readonly
clean
2C7B000
heap private
page read and write
clean
29C2000
unkown
page readonly
clean
29E5000
unkown
page readonly
clean
176000
heap default
page read and write
clean
5B0000
heap private
page read and write
clean
20000
unkown
page readonly
clean
70000
unkown
page read and write
clean
2C45000
heap private
page read and write
clean
2BE0000
unkown
page readonly
clean
1D47000
unkown
page readonly
clean
2AA2000
unkown
page readonly
clean
1E0000
unkown
page read and write
clean
28F2000
unkown
page readonly
clean
29B5000
unkown
page readonly
clean
2985000
unkown
page readonly
clean
2A55000
unkown
page readonly
clean
2A42000
unkown
page readonly
clean
27E2000
unkown
page readonly
clean
5C0000
unkown
page readonly
clean
376000
unkown
page read and write
clean
23C0000
heap private
page read and write
clean
5F0000
unkown
page readonly
clean
2892000
unkown
page readonly
clean
2A72000
unkown
page readonly
clean
3070000
unkown
page read and write
clean
60000
unkown
page readonly
clean
20000
unkown
page readonly
clean
2A25000
unkown
page readonly
clean
2D30000
unkown
page readonly
clean
29E4000
unkown
page readonly
clean
2922000
unkown
page readonly
clean
2A12000
unkown
page readonly
clean
2AE2000
unkown
page readonly
clean
60000
unkown
page read and write
clean
1B90000
unkown
page readonly
clean
D0000
unkown
page read and write
clean
5B4000
heap private
page read and write
clean
2460000
unkown
page readonly
clean
2F4000
heap private
page read and write
clean
337000
heap default
page read and write
clean
294D000
unkown
page readonly
clean
2279000
heap private
page read and write
clean
2C6000
unkown
page read and write
clean
2AB5000
unkown
page readonly
clean
460000
heap private
page read and write
clean
2D50000
unkown
page readonly
clean
2B90000
unkown
page readonly
clean
28C2000
unkown
page readonly
clean
2979000
unkown
page readonly
clean
29F2000
unkown
page readonly
clean
2ACD000
unkown
page readonly
clean
2862000
unkown
page readonly
clean
2A96000
unkown
page readonly
clean
197000
heap default
page read and write
clean
21E0000
unkown
page readonly
clean
334000
heap private
page read and write
clean
330000
heap default
page read and write
clean
ED000
unkown
page read and write
clean
29C9000
unkown
page readonly
clean
330000
heap private
page read and write
clean
2872000
unkown
page readonly
clean
2946000
unkown
page readonly
clean
BE000
heap default
page read and write
clean
27E8000
unkown
page readonly
clean
2150000
unkown
page readonly
clean
5C0000
unkown
page readonly
clean
2992000
unkown
page readonly
clean
1CE0000
unkown
page readonly
clean
290000
unkown
page read and write
clean
2AC9000
unkown
page readonly
clean
2792000
unkown
page readonly
clean
2854000
unkown
page readonly
clean
2999000
unkown
page readonly
clean
2240000
heap private
page read and write
clean
20D0000
heap private
page read and write
clean
2035000
heap private
page read and write
clean
29A2000
unkown
page readonly
clean
2270000
heap private
page read and write
clean
2662000
unkown
page readonly
clean
2310000
unkown
page readonly
clean
2668000
unkown
page readonly
clean
2170000
heap private
page read and write
clean
2B49000
unkown
page readonly
clean
2935000
unkown
page readonly
clean
2949000
unkown
page readonly
clean
2969000
unkown
page readonly
clean
2905000
unkown
page readonly
clean
60000
unkown
page read and write
clean
2275000
heap private
page read and write
clean
137000
heap default
page read and write
clean
29C9000
unkown
page readonly
clean
2864000
unkown
page readonly
clean
28D5000
unkown
page readonly
clean
22C0000
unkown
page readonly
clean
2DEB000
heap private
page read and write
clean
2B52000
unkown
page readonly
clean
17B000
heap default
page read and write
clean
29E2000
unkown
page readonly
clean
2BC0000
unkown
page readonly
clean
23C9000
heap private
page read and write
clean
2905000
unkown
page readonly
clean
36E000
heap default
page read and write
clean
2DB5000
heap private
page read and write
clean
2D10000
unkown
page readonly
clean
1D77000
unkown
page readonly
clean
300000
unkown
page read and write
clean
2C20000
unkown
page read and write
clean
28D5000
unkown
page readonly
clean
340000
unkown
page read and write
clean
2BB0000
unkown
page readonly
clean
2160000
heap private
page read and write
clean
2A85000
unkown
page readonly
clean
28E6000
unkown
page readonly
clean
740000
unkown
page readonly
clean
87000
heap default
page read and write
clean
2952000
unkown
page readonly
clean
1CE000
heap default
page read and write
clean
2962000
unkown
page readonly
clean
80000
heap default
page read and write
clean
29B5000
unkown
page readonly
clean
2824000
unkown
page readonly
clean
2AC6000
unkown
page readonly
clean
1EC7000
unkown
page readonly
clean
28C2000
unkown
page readonly
clean
6BF000
unkown
page read and write
clean
2A15000
unkown
page readonly
clean
2976000
unkown
page readonly
clean
2916000
unkown
page readonly
clean
2BD0000
unkown
page readonly
clean
2E30000
unkown
page readonly
clean
F0000
unkown
page readonly
clean
2175000
heap private
page read and write
clean
A5E000
unkown
page read and write
clean
48F000
unkown
page read and write
clean
2922000
unkown
page readonly
clean
EB000
unkown
page read and write
clean
2030000
heap private
page read and write
clean
470000
unkown
page readonly
clean
2179000
heap private
page read and write
clean
206B000
heap private
page read and write
clean
2CC0000
unkown
page readonly
clean
B3F000
unkown
page read and write
clean
1DB000
unkown
page read and write
clean
2C00000
unkown
page readonly
clean
28A5000
unkown
page readonly
clean
2692000
unkown
page readonly
clean
2822000
unkown
page readonly
clean
2874000
unkown
page readonly
clean
2894000
unkown
page readonly
clean
440000
unkown
page readonly
clean
2965000
unkown
page readonly
clean
1B60000
unkown
page readonly
clean
2DB0000
heap private
page read and write
clean
464000
heap private
page read and write
clean
160000
unkown
page read and write
clean
230000
unkown
page readonly
clean
2AE9000
unkown
page readonly
clean
There are 201 hidden memdumps, click here to show them.