IOCReport

loading gif

Files

File Path
Type
Category
Malicious
http://nicklaussglen.buzz/011
URL
initial url
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\011[1].htm
HTML document, UTF-8 Unicode (with BOM) text, with CRLF line terminators
downloaded
malicious
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{C585FDE4-99CC-11EB-90E4-ECF4BB862DED}.dat
Microsoft Word Document
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{C585FDE6-99CC-11EB-90E4-ECF4BB862DED}.dat
Microsoft Word Document
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{C585FDE7-99CC-11EB-90E4-ECF4BB862DED}.dat
Microsoft Word Document
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\585b051251[1].js
ASCII text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\css[1].css
ASCII text
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\jquery-3.1.1.min[1].js
ASCII text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\jquery-3.2.1.slim.min[1].js
ASCII text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\011[1]
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\8[1].jpg
[TIFF image data, big-endian, direntries=12, height=709, bps=0, PhotometricIntepretation=RGB, orientation=upper-left, width=1200], baseline, precision 8, 1200x646, frames 3
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\bootstrap.min[1].css
ASCII text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\gmail[1].png
PNG image data, 1280 x 1280, 8-bit/color RGBA, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\jquery.min[1].js
ASCII text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\adobe[1].jpg
JPEG image data, JFIF standard 1.02, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 400x400, frames 3
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\free-v4-shims.min[1].css
ASCII text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\free.min[1].css
ASCII text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\hover[1].css
ASCII text
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\outlook1[1].png
PNG image data, 26 x 26, 8-bit/color RGBA, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\011[1]
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\bootstrap.min[1].js
ASCII text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\office3651[1].png
PNG image data, 187 x 188, 8-bit/color RGBA, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\other1[1].png
PNG image data, 190 x 187, 8-bit/color RGBA, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\popper.min[1].js
ASCII text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Temp\~DF3B2F4095378D9A2A.TMP
data
dropped
clean
C:\Users\user\AppData\Local\Temp\~DF4835BC9D9DDAD3A2.TMP
data
dropped
clean
C:\Users\user\AppData\Local\Temp\~DF4A49C1F6EF59D352.TMP
data
dropped
clean
There are 17 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\internet explorer\iexplore.exe
'C:\Program Files\Internet Explorer\iexplore.exe' -Embedding
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:4600 CREDAT:17410 /prefetch:2
clean

URLs

Name
IP
Malicious
https://nicklaussglen.buzz/011/
malicious
https://nicklaussglen.buzz/011/
unknown
malicious
http://nicklaussglen.buzz/011
104.21.95.21
malicious
https://nicklaussglen.buzz/011/Root
unknown
malicious
http://nicklaussglen.buzz/011/
104.21.95.21
malicious
https://nicklaussglen.buzz/011/$Share
unknown
malicious
http://ianlunn.github.io/Hover/)
unknown
clean
https://ka-f.fontawesome.com
unknown
clean
https://code.jquery.com/jquery-3.2.1.slim.min.js
unknown
clean
https://code.jquery.com/jquery-3.1.1.min.js
unknown
clean
https://code.jquery.com/jquery-3.3.1.js
unknown
clean
https://maxcdn.bootstrapcdn.com/bootstrap/4.0.0/css/bootstrap.min.css
unknown
clean
https://fontawesome.com/license/free
unknown
clean
https://fontawesome.com
unknown
clean
https://kit.fontawesome.com
unknown
clean
https://github.com/twbs/bootstrap/graphs/contributors)
unknown
clean
https://cdnjs.cloudflare.com/ajax/libs/popper.js/1.12.9/umd/popper.min.js
unknown
clean
https://login.microsoftonline.com/common/login
unknown
clean
https://getbootstrap.com)
unknown
clean
http://ianlunn.co.uk/
unknown
clean
https://github.com/twbs/bootstrap/blob/master/LICENSE)
unknown
clean
https://github.com/IanLunn/Hover
unknown
clean
http://opensource.org/licenses/MIT).
unknown
clean
https://kit.fontawesome.com/585b051251.js
unknown
clean
https://maxcdn.bootstrapcdn.com/bootstrap/4.0.0/js/bootstrap.min.js
unknown
clean
There are 15 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
nicklaussglen.buzz
104.21.95.21
malicious
cdnjs.cloudflare.com
104.16.19.94
clean
maxcdn.bootstrapcdn.com
104.18.11.207
clean
ka-f.fontawesome.com
unknown
clean
code.jquery.com
unknown
clean
kit.fontawesome.com
unknown
clean

IPs

IP
Domain
Country
Malicious
104.21.95.21
nicklaussglen.buzz
United States
malicious
104.18.11.207
maxcdn.bootstrapcdn.com
United States
clean
104.16.19.94
cdnjs.cloudflare.com
United States
clean

Registry

Path
Value
Malicious
C:\Program Files\internet explorer\iexplore.exe
{C585FDE4-99CC-11EB-90E4-ECF4BB862DED}
clean
C:\Program Files\internet explorer\iexplore.exe
AdminActive
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
Blocked
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
LoadTimeArray
clean
C:\Program Files\internet explorer\iexplore.exe
LoadTimeArray
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
Blocked
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
LoadTimeArray
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
LoadTimeArray
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
@C:\Windows\System32\ieframe.dll,-912
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
@C:\Windows\System32\ieframe.dll,-904
clean
There are 12 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
7FF4FAA0D000
unkown
page readonly
clean
7FF4FA9A0000
unkown
page readonly
clean
27DAD8C4000
unkown
page read and write
clean
7FF5933A0000
unkown
page readonly
clean
27DAF802000
unkown
page read and write
clean
7FF4F8C8D000
unkown
page readonly
clean
7FF4FA954000
unkown
page readonly
clean
7FF4FA9A2000
unkown
page readonly
clean
7FF593418000
unkown
page readonly
clean
18B76130000
heap default
page read and write
clean
7FF4F8D29000
unkown
page readonly
clean
C0FB8FF000
unkown
page read and write
clean
4BAB07C000
unkown
page read and write
clean
27DAF947000
unkown
page read and write
clean
7FF593343000
unkown
page readonly
clean
7FF593667000
unkown
page readonly
clean
7FF5931E3000
unkown
page readonly
clean
7FF593587000
unkown
page readonly
clean
27DAD8DE000
unkown
page read and write
clean
7FF59357A000
unkown
page readonly
clean
1A587BAB000
heap default
page read and write
clean
7FF4F8CA6000
unkown
page readonly
clean
7FF5935AC000
unkown
page readonly
clean
C0FB59F000
unkown
page read and write
clean
46AD3FC000
unkown
page read and write
clean
7FF593571000
unkown
page readonly
clean
7FF4FAA16000
unkown
page readonly
clean
7FF59360E000
unkown
page readonly
clean
27DAF7A0000
unkown
page read and write
clean
7FF59363D000
unkown
page readonly
clean
7FF5934E7000
unkown
page readonly
clean
1A589640000
heap private
page read and write
clean
1A5879C0000
unkown
page readonly
clean
18B760F0000
unkown
page read and write
clean
7FF593584000
unkown
page readonly
clean
7FF4F8C65000
unkown
page readonly
clean
18B75FA0000
unkown
page readonly
clean
27DAF915000
unkown
page read and write
clean
7FF4F8C9C000
unkown
page readonly
clean
7FF59364C000
unkown
page readonly
clean
4BAB37F000
unkown
page read and write
clean
C0FBC7D000
unkown
page read and write
clean
7FF4F8CAC000
unkown
page readonly
clean
1A589A30000
heap private
page read and write
clean
7FF593395000
unkown
page readonly
clean
7FF4FA232000
unkown
page readonly
clean
27DADAD0000
unkown
page write copy
clean
27DAD7D0000
heap default
page read and write
clean
27DAD902000
unkown
page read and write
clean
27DAF989000
unkown
page read and write
clean
27DAD8B1000
unkown
page read and write
clean
46ACF8E000
unkown
page read and write
clean
27DAF790000
unkown
page readonly
clean
27DAD854000
unkown
page read and write
clean
1A587A90000
unkown
page read and write
clean
27DAF2C0000
unkown
page read and write
clean
7FF593665000
unkown
page readonly
clean
7FF4FAA2C000
unkown
page readonly
clean
4BAB2FF000
unkown
page read and write
clean
18B760D0000
unkown
page read and write
clean
7FF4F8C96000
unkown
page readonly
clean
7FF5934E3000
unkown
page readonly
clean
1A587AE0000
unkown
page readonly
clean
7FF4F8D29000
unkown
page readonly
clean
7FF59342A000
unkown
page readonly
clean
7FF5936D1000
unkown
page readonly
clean
7FF5936CE000
unkown
page readonly
clean
7FF593677000
unkown
page readonly
clean
7FF4FAA47000
unkown
page readonly
clean
C0FB9F9000
unkown
page read and write
clean
7FF59354C000
unkown
page readonly
clean
1A588030000
unkown
page readonly
clean
27DAD813000
unkown
page read and write
clean
7FF4FA6BC000
unkown
page readonly
clean
1A587CA0000
unkown
page readonly
clean
7FF4F8C5E000
unkown
page readonly
clean
1A587960000
unkown
page readonly
clean
7FF593347000
unkown
page readonly
clean
4BAB3FE000
unkown
page read and write
clean
7FF4FA9B6000
unkown
page readonly
clean
7FF4F8CB5000
unkown
page readonly
clean
7FF4F8C3A000
unkown
page readonly
clean
7FF4FAA40000
unkown
page readonly
clean
7FF593387000
unkown
page readonly
clean
7FF4F8C38000
unkown
page readonly
clean
18B7613B000
heap default
page read and write
clean
7FF4FAA52000
unkown
page readonly
clean
7FF4FAA44000
unkown
page readonly
clean
27DADB20000
unkown
page readonly
clean
27DAF740000
heap private
page read and write
clean
1A587B30000
unkown
page readonly
clean
7FF5935AA000
unkown
page readonly
clean
18B76345000
heap private
page read and write
clean
7FF593545000
unkown
page readonly
clean
1A587AD0000
unkown
page readonly
clean
7FF5935E6000
unkown
page readonly
clean
27DAD89C000
unkown
page read and write
clean
1A587AB0000
unkown
page read and write
clean
7FF593591000
unkown
page readonly
clean
46AD47E000
unkown
page read and write
clean
1A58983F000
heap private
page read and write
clean
27DAD8A6000
unkown
page read and write
clean
1A587B60000
heap private
page read and write
clean
7FF4FA9B8000
unkown
page readonly
clean
7FF4FAAA9000
unkown
page readonly
clean
27DADA00000
unkown
page readonly
clean
7FF592D95000
unkown
page readonly
clean
18B76340000
heap private
page read and write
clean
46ACF0E000
unkown
page read and write
clean
7FF4FAA35000
unkown
page readonly
clean
1A587B95000
heap private
page read and write
clean
C0FB51B000
unkown
page read and write
clean
1A587BA0000
heap default
page read and write
clean
7FF4FAA1C000
unkown
page readonly
clean
27DAD8E0000
unkown
page read and write
clean
C0FBBFB000
unkown
page read and write
clean
27DB0010000
unkown
page read and write
clean
7FF4FA9E5000
unkown
page readonly
clean
7FF59345F000
unkown
page readonly
clean
27DAD8CC000
unkown
page read and write
clean
C0FBB7C000
unkown
page read and write
clean
27DAD913000
unkown
page read and write
clean
4BAB1FE000
unkown
page read and write
clean
7FF5935FA000
unkown
page readonly
clean
18B76350000
unkown
page readonly
clean
27DAF900000
unkown
page read and write
clean
7FF4F8C79000
unkown
page readonly
clean
7FF4FA9DE000
unkown
page readonly
clean
7FF5936D9000
unkown
page readonly
clean
7FF5935E8000
unkown
page readonly
clean
46AD37E000
unkown
page read and write
clean
27DADEB0000
unkown
page readonly
clean
1A589440000
unkown
page readonly
clean
7FF4FA94E000
unkown
page readonly
clean
27DAF720000
unkown
page read and write
clean
C0FBA7E000
unkown
page read and write
clean
7FF4F8CC2000
unkown
page readonly
clean
7FF4FAA9E000
unkown
page readonly
clean
1A587B20000
unkown
page readonly
clean
7FF5935BC000
unkown
page readonly
clean
7FF5936D9000
unkown
page readonly
clean
7FF4FAAA1000
unkown
page readonly
clean
18B7615F000
heap default
page read and write
clean
7FF593656000
unkown
page readonly
clean
27DAD856000
unkown
page read and write
clean
C0FBAFA000
unkown
page read and write
clean
7FF59335C000
unkown
page readonly
clean
27DAD893000
unkown
page read and write
clean
7FF593629000
unkown
page readonly
clean
7FF4FA723000
unkown
page readonly
clean
7FF593674000
unkown
page readonly
clean
7FF4FAA26000
unkown
page readonly
clean
C0FB879000
unkown
page read and write
clean
7FF5935C8000
unkown
page readonly
clean
7FF5935B7000
unkown
page readonly
clean
7FF59338E000
unkown
page readonly
clean
7FF59358A000
unkown
page readonly
clean
7FF593334000
unkown
page readonly
clean
27DAF902000
unkown
page read and write
clean
7FF4FAAA9000
unkown
page readonly
clean
7FF5935E2000
unkown
page readonly
clean
7FF5935D2000
unkown
page readonly
clean
7FF4FA94A000
unkown
page readonly
clean
1A587BDA000
heap default
page read and write
clean
7FF4FA9F9000
unkown
page readonly
clean
7FF4FA9BA000
unkown
page readonly
clean
7FF4FA9CA000
unkown
page readonly
clean
27DAD842000
unkown
page read and write
clean
7FF4F8D1E000
unkown
page readonly
clean
18B7614F000
heap default
page read and write
clean
7FF593646000
unkown
page readonly
clean
7FF4FAA11000
unkown
page readonly
clean
7FF4F8D21000
unkown
page readonly
clean
7FF59343E000
unkown
page readonly
clean
27DAF7B0000
unkown
page readonly
clean
7FF593641000
unkown
page readonly
clean
7FF593440000
unkown
page readonly
clean
7FF5933FB000
unkown
page readonly
clean
27DAD800000
unkown
page read and write
clean
7FF5934C8000
unkown
page readonly
clean
4BAB17F000
unkown
page read and write
clean
C0FB97F000
unkown
page read and write
clean
27DAD885000
unkown
page read and write
clean
7FF4FA72C000
unkown
page readonly
clean
7FF59365C000
unkown
page readonly
clean
7FF5935B3000
unkown
page readonly
clean
7FF5935D0000
unkown
page readonly
clean
1A587B40000
unkown
page readonly
clean
7FF59361F000
unkown
page readonly
clean
46AD27D000
unkown
page read and write
clean
4BAB0FE000
unkown
page read and write
clean
27DAD829000
unkown
page read and write
clean
1A587B90000
heap private
page read and write
clean
1A589740000
heap private
page read and write
clean
7FF593615000
unkown
page readonly
clean
7FF59320D000
unkown
page readonly
clean
46ACE8C000
unkown
page read and write
clean
27DAD7E0000
unkown
page readonly
clean
27DAF730000
unkown
page readonly
clean
27DAF3C0000
unkown
page readonly
clean
7FF59340C000
unkown
page readonly
clean
7FF593670000
unkown
page readonly
clean
27DAD770000
heap private
page read and write
clean
7FF4FAA4D000
unkown
page readonly
clean
18B76110000
unkown
page readonly
clean
18B76000000
unkown
page readonly
clean
27DAF7D0000
unkown
page readonly
clean
There are 197 hidden memdumps, click here to show them.

DOM / HTML

URL
Malicious
https://nicklaussglen.buzz/011/
malicious