IOCReport

loading gif

Files

File Path
Type
Category
Malicious
PAGO.xlsx
CDFV2 Encrypted
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XNHC0JWC\svchost[1].exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
downloaded
malicious
C:\Users\user\Desktop\~$PAGO.xlsx
data
dropped
malicious
C:\Users\Public\vbc.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\3F6ihf[1].htm
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\1015AEA3.jpeg
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 333x151, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\2EF57FF8.png
PNG image data, 992 x 192, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\41D443A9.jpeg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 220x220, segment length 16, baseline, precision 8, 178x124, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\4890E2DA.jpeg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 220x220, segment length 16, baseline, precision 8, 88x89, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\4B3408F0.emf
Windows Enhanced Metafile (EMF) image data version 0x10000
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\5E7712AA.png
PNG image data, 1268 x 540, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\696809D7.png
PNG image data, 1686 x 725, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\6CA41431.emf
Windows Enhanced Metafile (EMF) image data version 0x10000
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\715928FD.jpeg
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 333x151, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\806800C6.jpeg
gd-jpeg v1.0 (using IJG JPEG v80), quality = 90", baseline, precision 8, 700x990, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\8299D048.jpeg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 220x220, segment length 16, baseline, precision 8, 88x89, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\84B2BE14.jpeg
gd-jpeg v1.0 (using IJG JPEG v80), quality = 90", baseline, precision 8, 700x990, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\863DC596.png
PNG image data, 992 x 192, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\91086113.jpeg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 220x220, segment length 16, baseline, precision 8, 178x124, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\A1EB740D.png
PNG image data, 1686 x 725, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\B2AC4F99.jpeg
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 191x263, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\B982CC9F.jpeg
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 191x263, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\C43329EC.png
PNG image data, 1268 x 540, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\DD298C7E.emf
Windows Enhanced Metafile (EMF) image data version 0x10000
dropped
clean
C:\Users\user\AppData\Local\Temp\Excel8.0\MSForms.exd
data
dropped
clean
There are 15 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
'C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE' -Embedding
malicious
C:\Users\Public\vbc.exe
'C:\Users\Public\vbc.exe'
malicious
C:\Users\Public\vbc.exe
C:\Users\Public\vbc.exe
malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
clean

URLs

Name
IP
Malicious
http://wsdysuresbonescagegp.dns.army/documenpt/svchost.exe
103.153.76.181
malicious
http://127.0.0.1:HTTP/1.1
unknown
clean
http://DynDns.comDynDNS
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip%tordir%%ha
unknown
clean
http://smtp.lpsinvest.com
unknown
clean
https://dist.nuget.org/win-x86-commandline/latest/nuget.exe
unknown
clean
https://github.com/d-haxton/HaxtonBot/archive/master.zip
unknown
clean
http://AFplKq.com
unknown
clean
https://api.ipify.org%GETMozilla/5.0
unknown
clean
http://www.%s.comPA
unknown
clean
https://github.com/Spegeli/Pokemon-Go-Rocket-API/archive/master.zip
unknown
clean
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
unknown
clean
https://api.ipify.org%
unknown
clean
https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip
unknown
clean
https://stackpath.bootstrapcdn.com/bootstrap/4.5.0/css/bootstrap.min.css
unknown
clean
https://x8nMk45g8ETcNqX.org
unknown
clean
There are 7 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
wsdysuresbonescagegp.dns.army
103.153.76.181
malicious
smtp.lpsinvest.com
5.10.29.169
malicious
is.gd
104.25.234.53
clean

IPs

IP
Domain
Country
Malicious
5.10.29.169
smtp.lpsinvest.com
United Kingdom
malicious
103.153.76.181
wsdysuresbonescagegp.dns.army
unknown
malicious
104.25.234.53
is.gd
United States
clean

Registry

Path
Value
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
{ 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
MTTT
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ReviewToken
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
VBAFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EF325
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
FontCachePath
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DefaultSheetR2L
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
UseSystemSeparators
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ThousandsSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DecimalSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
h<2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F4319
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F5BD6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 21
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
LastPurgeTime
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EXCELFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
NULL
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F4319
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F4319
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F4319
clean
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
EquationEditorFilesIntl_1033
clean
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
SavedLegacySettings
clean
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
Blob
clean
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
Blob
clean
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
Blob
clean
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
Blob
clean
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
Blob
clean
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
Blob
clean
There are 197 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
402000
unkown
page execute and read and write
malicious
2658000
unkown
page read and write
malicious
347C000
unkown
page read and write
malicious
25B1000
unkown
page read and write
malicious
24AB000
unkown
page read and write
malicious
775000
unkown
page read and write
clean
835000
unkown
page read and write
clean
7A0000
unkown
page read and write
clean
F80000
unkown image
page readonly
clean
249F000
unkown
page read and write
clean
51D000
heap default
page read and write
clean
305000
unkown
page read and write
clean
15B000
unkown
page execute and read and write
clean
770000
unkown
page read and write
clean
7EFDF000
unkown
page read and write
clean
300000
unkown
page read and write
clean
831000
unkown
page read and write
clean
5C0000
unkown
page read and write
clean
2E0000
unkown
page execute and read and write
clean
308000
unkown
page read and write
clean
305000
unkown
page read and write
clean
282000
unkown
page read and write
clean
300000
unkown
page read and write
clean
5E0000
heap private
page read and write
clean
990000
heap private
page read and write
clean
124000
unkown
page read and write
clean
830000
unkown
page read and write
clean
50CE000
stack
page read and write
clean
300000
unkown
page read and write
clean
5EF5000
unkown
page readonly
clean
790000
unkown
page read and write
clean
300000
unkown
page read and write
clean
5E8D000
unkown
page readonly
clean
28A000
unkown
page execute and read and write
clean
5C0000
unkown
page read and write
clean
772000
unkown
page read and write
clean
840000
unkown
page read and write
clean
13A000
unkown
page read and write
clean
770000
unkown
page read and write
clean
775000
unkown
page read and write
clean
A50000
unkown
page read and write
clean
830000
unkown
page read and write
clean
305000
unkown
page read and write
clean
300000
unkown
page read and write
clean
A50000
unkown
page read and write
clean
7EFDF000
unkown
page read and write
clean
999000
heap private
page read and write
clean
305000
unkown
page read and write
clean
310000
unkown
page read and write
clean
775000
unkown
page read and write
clean
6B40000
heap private
page read and write
clean
830000
unkown
page read and write
clean
51AC000
unkown
page read and write
clean
C40000
unkown
page read and write
clean
830000
unkown
page read and write
clean
5D84000
unkown
page readonly
clean
A60000
unkown
page read and write
clean
772000
unkown
page read and write
clean
5DA2000
unkown
page readonly
clean
5E15000
unkown
page readonly
clean
553000
heap default
page read and write
clean
519D000
unkown
page read and write
clean
29B000
unkown
page execute and read and write
clean
41E000
unkown
page read and write
clean
20000
unkown
page read and write
clean
5191000
unkown
page read and write
clean
5360000
unkown
page read and write
clean
51B0000
heap private
page read and write
clean
770000
unkown
page read and write
clean
760000
unkown
page read and write
clean
320000
unkown
page read and write
clean
45B0000
unkown
page readonly
clean
12D000
unkown
page execute and read and write
clean
7B0000
unkown
page read and write
clean
20000
unkown
page read and write
clean
A54000
unkown
page read and write
clean
7C0000
unkown
page readonly
clean
A55000
unkown
page read and write
clean
295000
unkown
page execute and read and write
clean
780000
unkown
page execute and read and write
clean
5BE7000
unkown
page read and write
clean
770000
unkown
page readonly
clean
B30000
unkown
page read and write
clean
25AF000
unkown
page read and write
clean
375A000
unkown
page read and write
clean
157000
unkown
page execute and read and write
clean
4D3E000
unkown
page read and write
clean
F82000
unkown image
page execute read
clean
380000
heap private
page read and write
clean
A50000
unkown
page read and write
clean
6B5000
heap default
page read and write
clean
305000
unkown
page read and write
clean
780000
unkown
page read and write
clean
5215000
unkown
page read and write
clean
300000
unkown
page read and write
clean
5CE000
unkown
page read and write
clean
4F00000
heap private
page read and write
clean
300000
unkown
page read and write
clean
5D0000
unkown
page read and write
clean
310000
unkown
page read and write
clean
4A1E000
unkown
page read and write | page guard
clean
152000
unkown
page read and write
clean
680000
unkown
page read and write
clean
660000
unkown
page read and write
clean
300000
unkown
page read and write
clean
26B7000
unkown
page read and write
clean
155000
unkown
page execute and read and write
clean
790000
unkown
page read and write
clean
575000
heap default
page read and write
clean
2D0000
unkown
page execute and read and write
clean
292000
unkown
page read and write
clean
627000
heap default
page read and write
clean
688000
unkown
page read and write
clean
84B000
unkown
page read and write
clean
690000
unkown
page read and write
clean
5E62000
unkown
page readonly
clean
830000
unkown
page read and write
clean
770000
unkown
page read and write
clean
3471000
unkown
page read and write
clean
130000
unkown
page read and write
clean
5F09000
unkown
page readonly
clean
140000
unkown
page read and write
clean
5C0000
unkown
page read and write
clean
F80000
unkown image
page readonly
clean
BF2E000
stack
page read and write
clean
7C3000
unkown
page read and write
clean
3FE000
unkown
page read and write
clean
790000
unkown
page read and write
clean
660000
unkown
page read and write
clean
2D7000
unkown
page read and write
clean
770000
unkown
page read and write
clean
790000
unkown
page read and write
clean
790000
unkown
page read and write
clean
3D0000
unkown
page read and write
clean
770000
unkown
page read and write
clean
5E6C000
unkown
page read and write
clean
A51000
unkown
page read and write
clean
5D62000
unkown
page readonly
clean
663000
unkown
page read and write
clean
2F0000
unkown
page readonly
clean
B8C000
unkown
page read and write
clean
572000
unkown
page read and write
clean
720000
unkown
page read and write
clean
790000
unkown
page read and write
clean
305000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
7A0000
unkown
page read and write
clean
5F25000
unkown
page readonly
clean
770000
unkown
page read and write
clean
305000
unkown
page read and write
clean
DFB000
unkown
page read and write
clean
780000
unkown
page read and write
clean
56CE000
unkown
page read and write
clean
50D0000
unkown
page read and write
clean
F80000
unkown image
page readonly
clean
6D2000
heap default
page read and write
clean
4D0000
heap default
page read and write
clean
5C0000
unkown
page read and write
clean
300000
unkown
page read and write
clean
305000
unkown
page read and write
clean
7EF58000
unkown
page execute and read and write
clean
75D000
unkown
page read and write
clean
300000
unkown
page read and write
clean
300000
unkown
page read and write
clean
A60000
unkown
page read and write
clean
559000
heap default
page read and write
clean
840000
unkown
page read and write
clean
27D000
unkown
page execute and read and write
clean
7E0000
unkown
page read and write
clean
102C000
unkown image
page readonly
clean
305000
unkown
page read and write
clean
24B8000
unkown
page read and write
clean
F80000
unkown image
page readonly
clean
770000
unkown
page read and write
clean
102C000
unkown image
page readonly
clean
3C4000
unkown
page read and write
clean
45C0000
unkown
page readonly
clean
4B05000
heap private
page read and write
clean
51ED000
unkown
page read and write
clean
7A0000
unkown
page read and write
clean
300000
unkown
page read and write
clean
5BF5000
unkown
page read and write
clean
150000
unkown
page read and write
clean
F82000
unkown image
page execute read
clean
450000
heap private
page read and write
clean
86E000
unkown
page read and write
clean
DF0000
unkown
page read and write
clean
770000
unkown
page read and write
clean
830000
unkown
page read and write
clean
26EC000
unkown
page read and write
clean
300000
unkown
page read and write
clean
850000
unkown
page read and write
clean
7C6000
unkown
page read and write
clean
59DF000
unkown
page read and write
clean
5820000
unkown
page readonly
clean
775000
unkown
page read and write
clean
5E4000
heap private
page read and write
clean
52D0000
unkown
page read and write
clean
300000
unkown
page read and write
clean
1AA000
unkown
page read and write
clean
5E45000
unkown
page readonly
clean
5C0000
unkown
page read and write
clean
300000
unkown
page read and write
clean
5AC0000
heap private
page read and write
clean
7D0000
unkown
page read and write
clean
662E000
unkown
page read and write
clean
680000
unkown
page read and write
clean
795000
unkown
page read and write
clean
300000
unkown
page read and write
clean
5398000
heap private
page read and write
clean
F6E000
unkown
page read and write
clean
C10000
unkown
page readonly
clean
4A40000
heap private
page read and write
clean
5820000
unkown
page read and write
clean
300000
unkown
page read and write
clean
5610000
unkown
page read and write
clean
775000
unkown
page read and write
clean
7C0000
unkown
page read and write
clean
7A0000
unkown
page read and write
clean
4B4E000
stack
page read and write
clean
5390000
heap private
page read and write
clean
7E0000
unkown
page read and write
clean
310000
unkown
page read and write
clean
4E30000
unkown
page read and write
clean
830000
unkown
page read and write
clean
7C0000
unkown
page read and write
clean
830000
unkown
page read and write
clean
851000
unkown
page read and write
clean
6092000
unkown
page readonly
clean
35B1000
unkown
page read and write
clean
7A0000
unkown
page read and write
clean
A77000
heap private
page read and write
clean
7E0000
unkown
page read and write
clean
55FE000
unkown
page read and write
clean
300000
unkown
page read and write
clean
4F10000
unkown
page read and write
clean
770000
unkown
page read and write
clean
7B0000
unkown
page read and write
clean
660000
unkown
page read and write
clean
24A3000
unkown
page read and write
clean
7A0000
unkown
page read and write
clean
490000
heap default
page read and write
clean
45BE000
stack
page read and write
clean
850000
unkown
page read and write
clean
770000
unkown
page read and write
clean
7C0000
heap private
page execute and read and write
clean
305000
unkown
page read and write
clean
DF0000
unkown
page execute and read and write
clean
830000
unkown
page read and write
clean
B9CE000
stack
page read and write
clean
775000
unkown
page read and write
clean
5C0000
unkown
page read and write
clean
300000
unkown
page read and write
clean
A40000
unkown
page readonly
clean
7A0000
unkown
page read and write
clean
305000
unkown
page read and write
clean
63BE000
unkown
page read and write
clean
5800000
unkown
page readonly
clean
5108000
unkown
page read and write
clean
860000
unkown
page read and write
clean
7D0000
unkown
page read and write
clean
264E000
unkown
page read and write
clean
550E000
unkown
page read and write
clean
310000
unkown
page read and write
clean
F1F000
stack
page read and write
clean
660000
heap default
page read and write
clean
4EFC000
unkown
page read and write
clean
5E89000
unkown
page readonly
clean
4B50000
unkown
page readonly
clean
770000
unkown
page read and write
clean
780000
unkown
page read and write
clean
102C000
unkown image
page readonly
clean
5BA2000
unkown
page readonly
clean
110000
unkown
page read and write
clean
792000
unkown
page read and write
clean
581D000
unkown
page read and write
clean
5E70000
unkown
page readonly
clean
270000
unkown
page read and write
clean
A50000
unkown
page read and write
clean
268000
stack
page read and write
clean
775000
unkown
page read and write
clean
305000
unkown
page read and write
clean
775000
unkown
page read and write
clean
7C0000
unkown
page read and write
clean
340000
heap default
page read and write
clean
543B000
unkown
page read and write
clean
DE0000
heap private
page execute and read and write
clean
830000
unkown
page read and write
clean
305000
unkown
page read and write
clean
5C0000
unkown
page read and write
clean
7D0000
unkown
page read and write
clean
644000
heap default
page read and write
clean
790000
unkown
page read and write
clean
BD8F000
unkown
page read and write
clean
D8E000
unkown
page read and write | page guard
clean
83A000
unkown
page read and write
clean
60D0000
unkown
page readonly
clean
5BA8000
unkown
page readonly
clean
305000
unkown
page read and write
clean
320000
heap private
page read and write
clean
300000
unkown
page read and write
clean
2603000
unkown
page read and write
clean
69CF000
unkown
page read and write
clean
5DF6000
unkown
page readonly
clean
770000
unkown
page read and write
clean
834000
unkown
page read and write
clean
780000
unkown
page read and write
clean
840000
unkown
page read and write
clean
5E56000
unkown
page readonly
clean
305000
unkown
page read and write
clean
300000
unkown
page read and write
clean
5E32000
unkown
page readonly
clean
5BE0000
unkown
page read and write
clean
2E0000
unkown
page read and write
clean
790000
unkown
page read and write
clean
E00000
unkown
page read and write
clean
840000
unkown
page read and write
clean
620000
heap default
page read and write
clean
53D1000
unkown
page read and write
clean
24A1000
unkown
page read and write
clean
7A0000
unkown
page readonly
clean
770000
unkown
page read and write
clean
4F2000
heap default
page read and write
clean
7EF40000
unkown
page execute and read and write
clean
870000
heap private
page execute and read and write
clean
123000
unkown
page execute and read and write
clean
305000
unkown
page read and write
clean
305000
unkown
page read and write
clean
164000
unkown
page read and write
clean
5EC5000
unkown
page readonly
clean
C3E000
unkown
page read and write
clean
5D0000
unkown
page read and write
clean
4970000
unkown
page readonly
clean
3C0000
unkown
page read and write
clean
775000
unkown
page read and write
clean
780000
unkown
page read and write
clean
517D000
unkown
page read and write
clean
770000
unkown
page read and write
clean
780000
unkown
page read and write
clean
300000
unkown
page read and write
clean
330000
unkown
page read and write
clean
384000
heap private
page read and write
clean
54F0000
heap private
page read and write
clean
840000
unkown
page read and write
clean
84D7000
unkown
page read and write
clean
5C0000
unkown
page read and write
clean
7B0000
unkown
page read and write
clean
860000
unkown
page read and write
clean
F82000
unkown image
page execute read
clean
770000
unkown
page read and write
clean
830000
unkown
page read and write
clean
305000
unkown
page read and write
clean
3A2000
heap private
page read and write
clean
60F0000
unkown
page readonly
clean
4B00000
heap private
page read and write
clean
F80000
unkown image
page readonly
clean
6110000
unkown
page readonly
clean
310000
unkown
page read and write
clean
A60000
unkown
page read and write
clean
5ED9000
unkown
page readonly
clean
F0000
unkown
page read and write
clean
305000
unkown
page read and write
clean
300000
unkown
page read and write
clean
80000
unkown
page readonly
clean
622F000
stack
page read and write
clean
779000
unkown
page read and write
clean
770000
unkown
page read and write
clean
980000
unkown
page readonly
clean
7A0000
unkown
page read and write
clean
305000
unkown
page read and write
clean
770000
unkown
page read and write
clean
4F8F000
unkown
page read and write
clean
61D000
unkown
page read and write
clean
770000
unkown
page read and write
clean
830000
unkown
page read and write
clean
5DD2000
unkown
page readonly
clean
5DA4000
unkown
page readonly
clean
305000
unkown
page read and write
clean
790000
unkown
page read and write
clean
305000
unkown
page read and write
clean
840000
unkown
page read and write
clean
D8F000
unkown
page read and write
clean
4C8E000
unkown
page read and write
clean
320000
unkown
page read and write
clean
5197000
unkown
page read and write
clean
142000
unkown
page read and write
clean
5394000
heap private
page read and write
clean
300000
unkown
page read and write
clean
370000
unkown
page readonly
clean
4DC000
heap default
page read and write
clean
4DD0000
heap private
page execute and read and write
clean
5B3E000
unkown
page read and write
clean
5E26000
unkown
page readonly
clean
5D0000
unkown
page read and write
clean
770000
unkown
page read and write
clean
5170000
heap private
page read and write
clean
573000
heap default
page read and write
clean
6FD000
heap default
page read and write
clean
7BF000
unkown
page read and write
clean
537000
heap default
page read and write
clean
770000
unkown
page read and write
clean
1070000
unkown
page readonly
clean
5156000
unkown
page read and write
clean
16D000
unkown
page execute and read and write
clean
5C0000
unkown
page read and write
clean
770000
unkown
page read and write
clean
5CA2000
unkown
page readonly
clean
4A1F000
unkown
page read and write
clean
7A0000
unkown
page read and write
clean
300000
unkown
page read and write
clean
597E000
unkown
page read and write
clean
7C0000
unkown
page read and write
clean
770000
unkown
page read and write
clean
3479000
unkown
page read and write
clean
CF0000
unkown
page write copy
clean
B40000
unkown
page read and write
clean
537D000
unkown
page read and write
clean
300000
unkown
page read and write
clean
24B4000
unkown
page read and write
clean
310000
unkown
page read and write
clean
BEC000
unkown
page read and write
clean
770000
unkown
page read and write
clean
5D0000
unkown
page read and write
clean
850000
unkown
page read and write
clean
76E000
unkown
page read and write
clean
26EA000
unkown
page read and write
clean
5600000
unkown
page read and write
clean
5D0000
unkown
page readonly
clean
300000
unkown
page read and write
clean
305000
unkown
page read and write
clean
5C0000
unkown
page read and write
clean
4890000
unkown
page readonly
clean
5EA2000
unkown
page readonly
clean
65E000
unkown
page read and write
clean
80000
unkown
page readonly
clean
1D0000
unkown
page read and write
clean
580000
unkown
page execute and read and write
clean
146000
unkown
page execute and read and write
clean
860000
unkown
page read and write
clean
E10000
unkown
page read and write
clean
DDE000
unkown
page read and write
clean
5DE5000
unkown
page readonly
clean
4F0000
heap default
page read and write
clean
300000
unkown
page read and write
clean
775000
unkown
page read and write
clean
5BEC000
unkown
page read and write
clean
5C0000
unkown
page read and write
clean
4750000
unkown
page readonly
clean
30B000
unkown
page read and write
clean
53D0000
unkown
page read and write
clean
5F02000
unkown
page readonly
clean
7B0000
unkown
page read and write
clean
13D000
unkown
page execute and read and write
clean
25AE000
unkown
page read and write | page guard
clean
660000
unkown
page read and write
clean
7A0000
unkown
page read and write
clean
287000
unkown
page execute and read and write
clean
5B0000
unkown
page read and write
clean
775000
unkown
page read and write
clean
5D0000
unkown
page execute and read and write
clean
5C3000
unkown
page read and write
clean
682E000
unkown
page read and write
clean
840000
unkown
page read and write
clean
4B22000
heap private
page read and write
clean
308000
unkown
page read and write
clean
633E000
stack
page read and write
clean
8B0000
heap private
page read and write
clean
5D64000
unkown
page readonly
clean
51D0000
unkown
page read and write
clean
26F4000
unkown
page read and write
clean
790000
unkown
page read and write
clean
770000
unkown
page read and write
clean
5E75000
unkown
page readonly
clean
770000
unkown
page read and write
clean
F82000
unkown image
page execute read
clean
4A6E000
unkown
page read and write
clean
770000
unkown
page read and write
clean
5E02000
unkown
page readonly
clean
A70000
heap private
page read and write
clean
4F05000
heap private
page read and write
clean
670000
heap private
page read and write
clean
102C000
unkown image
page readonly
clean
4E0000
unkown
page readonly
clean
26B4000
unkown
page read and write
clean
66D000
heap default
page read and write
clean
790000
unkown
page read and write
clean
F20000
unkown
page read and write
clean
5B9E000
unkown
page read and write
clean
30B000
unkown
page read and write
clean
4B4000
heap default
page read and write
clean
770000
unkown
page read and write
clean
14A000
unkown
page execute and read and write
clean
A60000
unkown
page read and write
clean
780000
unkown
page read and write
clean
800000
unkown
page readonly
clean
770000
unkown
page read and write
clean
4DA000
heap default
page read and write
clean
474F000
unkown
page read and write
clean
6DC000
heap default
page read and write
clean
8C0000
unkown
page readonly
clean
5134000
unkown
page read and write
clean
5159000
unkown
page read and write
clean
305000
unkown
page read and write
clean
770000
unkown
page read and write
clean
775000
unkown
page read and write
clean
4E10000
unkown
page readonly
clean
5C0000
unkown
page read and write
clean
305000
unkown
page read and write
clean
5C0000
unkown
page read and write
clean
783000
unkown
page read and write
clean
5A0000
unkown
page read and write
clean
400000
unkown
page execute and read and write
clean
6DE000
heap default
page read and write
clean
770000
unkown
page read and write
clean
F80000
unkown image
page readonly
clean
770000
unkown
page read and write
clean
2471000
unkown
page read and write
clean
770000
unkown
page read and write
clean
770000
unkown
page read and write
clean
570000
unkown
page read and write
clean
BBCD000
stack
page read and write
clean
602000
heap private
page read and write
clean
300000
unkown
page read and write
clean
2636000
unkown
page read and write
clean
300000
unkown
page read and write
clean
DB0000
heap private
page execute and read and write
clean
5ED2000
unkown
page readonly
clean
305000
unkown
page read and write
clean
300000
unkown
page read and write
clean
7A0000
unkown
page read and write
clean
770000
heap private
page execute and read and write
clean
5C0000
unkown
page read and write
clean
300000
unkown
page read and write
clean
F1E000
unkown
page read and write
clean
4D7E000
unkown
page read and write
clean
5D82000
unkown
page readonly
clean
5EA9000
unkown
page readonly
clean
556C000
unkown
page read and write
clean
5166000
unkown
page read and write
clean
BD8E000
unkown
page read and write | page guard
clean
5E86000
unkown
page readonly
clean
720000
unkown
page read and write
clean
775000
unkown
page read and write
clean
52EE000
unkown
page read and write
clean
497000
heap default
page read and write
clean
770000
unkown
page read and write
clean
5C0B000
unkown
page read and write
clean
82E000
unkown
page read and write
clean
297000
unkown
page execute and read and write
clean
B90000
unkown
page read and write
clean
163000
unkown
page execute and read and write
clean
There are 541 hidden memdumps, click here to show them.