IOCReport

loading gif

Files

File Path
Type
Category
Malicious
https://vaccinecovid19.cra.ac.th/VaccineCOVID19/form/registration
URL
initial url
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{8CE55B2F-BF24-11EB-90E4-ECF4BB862DED}.dat
Microsoft Word Document
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{8CE55B31-BF24-11EB-90E4-ECF4BB862DED}.dat
Microsoft Word Document
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{8CE55B32-BF24-11EB-90E4-ECF4BB862DED}.dat
Microsoft Word Document
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\errorPageStrings[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\NewErrorPageTemplate[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\httpErrorPagesScripts[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\tlserror[1]
HTML document, UTF-8 Unicode (with BOM) text, with CRLF line terminators
downloaded
clean
C:\Users\user\AppData\Local\Temp\~DF11488D19FA3C340E.TMP
data
dropped
clean
C:\Users\user\AppData\Local\Temp\~DF9D5291095A25E853.TMP
data
dropped
clean
C:\Users\user\AppData\Local\Temp\~DFA8B32C6652EFFCF8.TMP
data
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Program Files\internet explorer\iexplore.exe
'C:\Program Files\Internet Explorer\iexplore.exe' -Embedding
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:4648 CREDAT:17410 /prefetch:2
clean

URLs

Name
IP
Malicious
https://vaccinecovid19.cra.ac.th/VaccineCOVID19/form/registration
unknown
clean
https://vaccinecovid19.cra.ac.th/VaccineCOVID19/form/registrationRoot
unknown
clean

Domains

Name
IP
Malicious
vaccinecovid19.cra.ac.th
104.21.53.156
clean

IPs

IP
Domain
Country
Malicious
104.21.53.156
vaccinecovid19.cra.ac.th
United States
clean

Registry

Path
Value
Malicious
C:\Program Files\internet explorer\iexplore.exe
{8CE55B2F-BF24-11EB-90E4-ECF4BB862DED}
clean
C:\Program Files\internet explorer\iexplore.exe
AdminActive
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
Blocked
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
LoadTimeArray
clean
C:\Program Files\internet explorer\iexplore.exe
LoadTimeArray
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
Blocked
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
LoadTimeArray
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
LoadTimeArray
clean
There are 10 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
17B8AC02000
unkown
page read and write
clean
7FF5EB4FA000
unkown
page readonly
clean
7FF52A9FC000
unkown
page readonly
clean
7FF5A1EAA000
unkown
page readonly
clean
2979B887000
unkown
page read and write
clean
2979B913000
unkown
page read and write
clean
2979B813000
unkown
page read and write
clean
7FF5A1E98000
unkown
page readonly
clean
7FF5A1EC5000
unkown
page readonly
clean
7FF5A1F06000
unkown
page readonly
clean
2979B88D000
unkown
page read and write
clean
7FF5EB5D9000
unkown
page readonly
clean
7FF52AA17000
unkown
page readonly
clean
2979B84E000
unkown
page read and write
clean
7FF52A883000
unkown
page readonly
clean
7FF5A1E5C000
unkown
page readonly
clean
17B8AC13000
unkown
page read and write
clean
7FF52A9C9000
unkown
page readonly
clean
7FF5EB39E000
unkown
page readonly
clean
9E117E000
unkown
page read and write
clean
2979C540000
unkown
page readonly
clean
2979B760000
heap private
page read and write
clean
17B8AC6A000
unkown
page read and write
clean
7FF5EB556000
unkown
page readonly
clean
7FF52A98A000
unkown
page readonly
clean
7FF5EB5D9000
unkown
page readonly
clean
126E11D0000
heap default
page read and write
clean
7FF52A9E6000
unkown
page readonly
clean
7FF5A1803000
unkown
page readonly
clean
17B8C670000
unkown
page read and write
clean
7FF5A1CF0000
unkown
page readonly
clean
17B8AB40000
unkown
page write copy
clean
7FF5EB3AA000
unkown
page readonly
clean
7FF5EB54C000
unkown
page readonly
clean
7FF5A1E5A000
unkown
page readonly
clean
B24387B000
unkown
page read and write
clean
7FF5A1E96000
unkown
page readonly
clean
17B8AD02000
unkown
page read and write
clean
7FF5EB565000
unkown
page readonly
clean
7FF52A92A000
unkown
page readonly
clean