IOCReport

loading gif

Files

File Path
Type
Category
Malicious
8OKQ6ogGRx.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{AE905FC9-AD44-11EB-90E4-ECF4BB862DED}.dat
Microsoft Word Document
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{AE905FCB-AD44-11EB-90E4-ECF4BB862DED}.dat
Microsoft Word Document
dropped
clean
C:\Users\user\AppData\Local\Temp\~DFFDCA7E35786F02EC.TMP
data
dropped
clean
C:\Users\user\AppData\Local\Temp\~DFFF4222CFAFFA654A.TMP
data
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Windows\System32\loaddll32.exe
loaddll32.exe 'C:\Users\user\Desktop\8OKQ6ogGRx.dll'
malicious
C:\Windows\SysWOW64\cmd.exe
cmd.exe /C rundll32.exe 'C:\Users\user\Desktop\8OKQ6ogGRx.dll',#1
clean
C:\Windows\SysWOW64\rundll32.exe
rundll32.exe C:\Users\user\Desktop\8OKQ6ogGRx.dll,Enterbeen
clean
C:\Windows\SysWOW64\rundll32.exe
rundll32.exe 'C:\Users\user\Desktop\8OKQ6ogGRx.dll',#1
clean
C:\Windows\SysWOW64\rundll32.exe
rundll32.exe C:\Users\user\Desktop\8OKQ6ogGRx.dll,Multiply
clean
C:\Program Files\internet explorer\iexplore.exe
'C:\Program Files\Internet Explorer\iexplore.exe' -Embedding
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:5212 CREDAT:17410 /prefetch:2
clean

Domains

Name
IP
Malicious
outlook.com
40.97.161.50
clean
HHN-efz.ms-acdc.office.com
40.101.138.2
clean
FRA-efz.ms-acdc.office.com
40.101.81.162
clean
www.outlook.com
unknown
clean
outlook.office365.com
unknown
clean

Registry

Path
Value
Malicious
C:\Program Files\internet explorer\iexplore.exe
{AE905FC9-AD44-11EB-90E4-ECF4BB862DED}
clean
C:\Program Files\internet explorer\iexplore.exe
AdminActive
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
Blocked
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
LoadTimeArray
clean
C:\Program Files\internet explorer\iexplore.exe
LoadTimeArray
clean
There are 1 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
3618000
heap private
page read and write
malicious
15E9A8F4000
unkown
page read and write
clean
7FF582B15000
unkown
page readonly
clean
BA0000
unkown
page read and write
clean
BA0000
unkown
page read and write
clean
7FF582973000
unkown
page readonly
clean
1F827813000
unkown
page read and write
clean
7FF58EEE9000
unkown
page readonly
clean
1F827D90000
unkown
page readonly
clean
15E9A9A4000
unkown
page write copy
clean
16CABF30000
unkown
page readonly
clean
21C57302000
unkown
page read and write
clean
A6546FE000
unkown
page read and write
clean
2A16246B000
unkown
page read and write
clean
BA0000
unkown
page read and write
clean
26EE000
unkown
page readonly
clean
7FF58EE2F000
unkown
page readonly
clean
7FF51CD88000
unkown
page readonly
clean
7FF5DA027000
unkown
page readonly
clean
30C0000
unkown
page read and write
clean
7FF5BBF1F000
unkown
page readonly
clean
1F146227000
unkown
page read and write
clean
7FF51CC85000
unkown
page readonly
clean
30C0000
unkown
page read and write
clean
30C0000
unkown
page read and write
clean
7FF5BB92E000
unkown
page readonly
clean
213E7069000
unkown
page read and write
clean
30C0000
unkown
page read and write
clean
660000
unkown
page read and write
clean
30C0000
unkown
page read and write
clean
6E0C0000
unkown image
page readonly
clean
BA0000
unkown
page read and write
clean
7FF51CFBE000
unkown
page readonly
clean
30C0000
unkown
page read and write
clean
245557C0000
heap private
page read and write
clean
BA0000
unkown
page read and write
clean
213E706C000
unkown
page read and write
clean
7FF5BB71A000
unkown
page readonly
clean
15E96220000
unkown
page readonly
clean
23EE08C0000
unkown
page write copy
clean
BA0000
unkown
page read and write
clean
16CAC04A000
unkown
page read and write
clean
30C0000
unkown
page read and write
clean
BA0000
unkown
page read and write
clean
30C0000
unkown
page read and write
clean
7FF5CB4E7000
unkown
page readonly
clean
7FF5689EC000
unkown
page readonly
clean
BA0000
unkown
page read and write
clean
23EE0870000
unkown
page readonly
clean
7FF5DA225000
unkown
page readonly
clean