IOCReport

loading gif

Files

File Path
Type
Category
Malicious
audit-367497006.xlsb
Microsoft Excel 2007+
initial sample
malicious
C:\Users\user\Desktop\~$audit-367497006.xlsb
data
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\2A108F49.png
PNG image data, 246 x 108, 8-bit/color RGB, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\5C50E7CA.png
PNG image data, 521 x 246, 8-bit/color RGB, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\8F304143.png
PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\9F7E393F.png
PNG image data, 490 x 30, 8-bit/color RGB, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\BA0F5CB6.png
PNG image data, 934 x 29, 8-bit/color RGB, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\DEFF0268.png
PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Temp\05A40000
data
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\UProof\CUSTOM.DIC
Little-endian UTF-16 Unicode text, with CR line terminators
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding
malicious
C:\Windows\SysWOW64\regsvr32.exe
regsvr32 -s ..\werty1.dll
malicious
C:\Windows\SysWOW64\regsvr32.exe
regsvr32 -s ..\werty2.dll
malicious

Domains

Name
IP
Malicious
forfacks.com
192.185.48.167
malicious
dreamhimalayan.com
192.185.113.120
clean

IPs

IP
Domain
Country
Malicious
192.185.48.167
forfacks.com
United States
malicious
192.185.113.120
dreamhimalayan.com
United States
clean

Registry

Path
Value
Malicious
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
l`+
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
m`+
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
LastBootTime
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
ReviewToken
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
49C0E
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
VBAFiles
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
MSForms
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
MSComctlLib
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
1
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
UpdateComplete
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
DefaultSheetR2L
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
UseSystemSeparators
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
ThousandsSeparator
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
DecimalSeparator
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
4A248
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
4A342
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
4A40D
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
4A565
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
/r+
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
ProductFiles
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
en-US
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
en-US
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
EXCELFiles
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
RoamingConfigurableSettings
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
RoamingLastSyncTime
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
RoamingLastWriteTime
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
ProductFiles
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
CacheReady
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
LastRequest
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
CacheReady
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
LastUpdate
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
NextUpdate
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
ProductFiles
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
ProductFiles
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
ProductFiles
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
ProductFiles
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
LastBootTime
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
LastPurgeTime
clean
There are 37 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
2CA8000
unkown
page readonly
clean
3097000
unkown
page read and write
clean
2CB3000
unkown
page readonly
clean
2BF0000
unkown
page readonly
clean
3310000
unkown
page readonly
clean
3320000
heap private
page read and write
clean
2537000
unkown
page readonly
clean
2C1A000
unkown
page readonly
clean
24D9000
unkown
page readonly
clean
2990000
unkown
page readonly
clean
2407000
unkown
page readonly
clean
2BAC000
unkown
page readonly
clean
2C71000
heap default
page read and write
clean
2AD7000
unkown
page readonly
clean
25D2000
unkown
page readonly
clean
253F000
unkown
page readonly
clean
2C50000
heap default
page read and write
clean
2C13000
unkown
page readonly
clean
2BDC000
unkown
page readonly
clean
2C3B000
unkown
page readonly
clean
2543000
unkown
page readonly
clean
2D50000
unkown
page readonly
clean
2BB3000
unkown
page readonly
clean
24EA000
unkown
page readonly
clean
2E20000
unkown
page readonly
clean
2FBB000
unkown
page read and write
clean
2CA2000
unkown
page readonly
clean
2551000
unkown
page readonly
clean
3330000
unkown
page readonly
clean
24DC000
unkown
page readonly
clean
2C36000
unkown
page readonly
clean
2C94000
unkown
page readonly
clean
253D000
unkown
page readonly
clean
2C0D000
unkown
page readonly
clean
28AC000
unkown
page read and write
clean
25B1000
unkown
page readonly
clean
2B21000
unkown
page read and write
clean
4630000
heap private
page read and write
clean
33F0000
heap default
page read and write
clean
2505000
unkown
page readonly
clean
2529000
unkown
page readonly
clean
2C5A000
heap default
page read and write
clean
28B4000
unkown
page readonly
clean
2BE3000
unkown
page readonly
clean
2980000
heap default
page read and write
clean
256B000
unkown
page readonly
clean
3680000
unkown
page readonly
clean
254F000
unkown
page readonly
clean
358A000
heap default
page read and write
clean
2C32000
unkown
page readonly
clean
2BEC000
unkown
page readonly
clean
2C07000
unkown
page readonly
clean
4640000
unkown
page readonly
clean
2566000
unkown
page readonly
clean
25D8000
unkown
page readonly
clean
25C4000
unkown
page readonly
clean
254A000
unkown
page readonly
clean
251C000
unkown
page readonly
clean
25B5000
unkown
page readonly
clean
25E3000
unkown
page readonly
clean
25E3000
unkown
page readonly
clean
2970000
unkown
page readonly
clean
2BD5000
unkown
page readonly
clean
2BA9000
unkown
page readonly
clean
2CB3000
unkown
page readonly
clean
2535000
unkown
page readonly
clean
29F0000
heap private
page read and write
clean
28EB000
unkown
page read and write
clean
2C1F000
unkown
page readonly
clean
2C81000
unkown
page readonly
clean
2C0F000
unkown
page readonly
clean
2BBA000
unkown
page readonly
clean
2B1D000
unkown
page read and write
clean
2520000
unkown
page readonly
clean
3580000
heap default
page read and write
clean
32F0000
unkown
page read and write
clean
3220000
unkown
page readonly
clean
2F7C000
unkown
page read and write
clean
24E3000
unkown
page readonly
clean
2513000
unkown
page readonly
clean
2950000
unkown
page read and write
clean
2BF9000
unkown
page readonly
clean
2C05000
unkown
page readonly
clean
309B000
unkown
page read and write
clean
35A1000
heap default
page read and write
clean
250C000
unkown
page readonly
clean
3400000
unkown
page readonly
clean
2562000
unkown
page readonly
clean
21E4000
unkown
page readonly
clean
2C85000
unkown
page readonly
clean
4FF0000
heap private
page read and write
clean
2C21000
unkown
page readonly
clean
There are 82 hidden memdumps, click here to show them.