IOCReport

loading gif

Files

File Path
Type
Category
Malicious
https://vaccinecovid19.cra.ac.th/VaccineCOVID19/form/registration_list
URL
initial url
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{DC2DE5EE-BF26-11EB-90E4-ECF4BB862DED}.dat
Microsoft Word Document
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{DC2DE5F0-BF26-11EB-90E4-ECF4BB862DED}.dat
Microsoft Word Document
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{DC2DE5F1-BF26-11EB-90E4-ECF4BB862DED}.dat
Microsoft Word Document
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\errorPageStrings[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\NewErrorPageTemplate[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\httpErrorPagesScripts[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\tlserror[1]
HTML document, UTF-8 Unicode (with BOM) text, with CRLF line terminators
downloaded
clean
C:\Users\user\AppData\Local\Temp\~DF3DDDF624476E4DCD.TMP
data
dropped
clean
C:\Users\user\AppData\Local\Temp\~DF8172BE3A0CD9D1D6.TMP
data
dropped
clean
C:\Users\user\AppData\Local\Temp\~DFA358B3134752E076.TMP
data
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Program Files\internet explorer\iexplore.exe
'C:\Program Files\Internet Explorer\iexplore.exe' -Embedding
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:6140 CREDAT:17410 /prefetch:2
clean

URLs

Name
IP
Malicious
https://vaccinecovid19.cra.ac.th/VaccineCOVID19/form/registration_list
unknown
clean
https://vaccinecovid19.cra.ac.th/VaccineCOVID19/form/registration_listRoot
unknown
clean

Domains

Name
IP
Malicious
vaccinecovid19.cra.ac.th
104.21.53.156
clean

IPs

IP
Domain
Country
Malicious
104.21.53.156
vaccinecovid19.cra.ac.th
United States
clean

Registry

Path
Value
Malicious
C:\Program Files\internet explorer\iexplore.exe
{DC2DE5EE-BF26-11EB-90E4-ECF4BB862DED}
clean
C:\Program Files\internet explorer\iexplore.exe
AdminActive
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
Blocked
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
LoadTimeArray
clean
C:\Program Files\internet explorer\iexplore.exe
LoadTimeArray
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
Blocked
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
LoadTimeArray
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
LoadTimeArray
clean
There are 10 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
D6B40FF000
unkown
page read and write
clean
22D40E02000
unkown
page read and write
clean
7FF5DA04E000
unkown
page readonly
clean
7FF5D9F2D000
unkown
page readonly
clean
22D405A0000
heap default
page read and write
clean
7FF5D9EDE000
unkown
page readonly
clean
7FF5DA09C000
unkown
page readonly
clean
22D41340000
unkown
page readonly
clean
7FF5DA022000
unkown
page readonly
clean
7FF5D9C20000
unkown
page readonly
clean
22D40600000
unkown
page read and write
clean
22D40800000
unkown
page readonly
clean
7FF5DA028000
unkown
page readonly
clean
7FF5DA119000
unkown
page readonly
clean
22D408D0000
unkown
page readonly
clean
22D40540000
heap private
page read and write
clean
7FF5D9E3A000
unkown
page readonly
clean
22D41000000
unkown
page readonly
clean
22D40700000
unkown
page read and write
clean
7FF5DA026000
unkown
page readonly
clean
7FF5D9E9F000
unkown
page readonly
clean
22D40627000
unkown
page read and write
clean
7FF5DA0B4000
unkown
page readonly
clean
22D40629000
unkown
page read and write
clean
7FF5DA111000
unkown
page readonly
clean
D6B3FF7000
unkown
page read and write
clean
D6B398B000
unkown
page read and write
clean
22D40702000
unkown
page read and write
clean
7FF5DA05F000
unkown
page readonly
clean
7FF5DA012000
unkown
page readonly
clean
22D4063C000
unkown
page read and write
clean
22D40655000
unkown
page read and write
clean
D6B3EFB000
unkown
page read and write
clean
7FF5D9C10000
unkown
page readonly
clean
22D40613000
unkown
page read and write
clean
7FF5DA0B0000
unkown
page readonly
clean
22D4064C000
unkown
page read and write
clean
22D405C0000
unkown
page readonly
clean
22D40708000
unkown
page read and write
clean
7FF5DA08C000
unkown
page readonly
clean
7FF5DA086000
unkown
page readonly
clean
22D405D0000
unkown
page read and write
clean
7FF5DA069000
unkown
page readonly
clean
7FF5DA096000
unkown
page readonly
clean
7FF5DA055000
unkown
page readonly
clean
7FF5D9F08000
unkown
page readonly
clean
7FF5DA07D000
unkown
page readonly
clean
7FF5D9F23000
unkown
page readonly
clean
7FF5DA0B7000
unkown
page readonly
clean
22D4064F000
unkown
page read and write
clean
22D405B0000
unkown
page readonly
clean
7FF5DA10E000
unkown
page readonly
clean
7FF5DA03A000
unkown
page readonly
clean
22D40689000
unkown
page read and write
clean
22D40671000
unkown
page read and write
clean
D6B3DF5000
unkown
page read and write
clean
7FF5D9D6D000
unkown
page readonly
clean
22D40652000
unkown
page read and write
clean
D6B3CFF000
unkown
page read and write
clean
7FF5D9EEA000
unkown
page readonly
clean
7FF5D9F8C000
unkown
page readonly
clean
7FF5D9F51000
unkown
page readonly
clean
7FF5DA010000
unkown
page readonly
clean
D6B41FF000
unkown
page read and write
clean
D6B3C7F000
unkown
page read and write
clean
7FF5D9C0A000
unkown
page readonly
clean
22D40713000
unkown
page read and write
clean
7FF5DA119000
unkown
page readonly
clean
7FF5DA0A5000
unkown
page readonly
clean
7FF5D9F57000
unkown
page readonly
clean
There are 60 hidden memdumps, click here to show them.