IOCReport

loading gif

Files

File Path
Type
Category
Malicious
Shipping-Documents.xlsx
CDFV2 Encrypted
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\regasm[1].exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
downloaded
malicious
C:\Users\user\Desktop\~$Shipping-Documents.xlsx
data
dropped
malicious
C:\Users\Public\vbc.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\1AE5E43D.png
PNG image data, 399 x 605, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\32420706.png
PNG image data, 566 x 429, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\4091E51A.jpeg
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 191x263, frames 3
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\5A2D31B2.png
PNG image data, 1268 x 540, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\63F24961.emf
Windows Enhanced Metafile (EMF) image data version 0x10000
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\6BC1535.png
PNG image data, 1686 x 725, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\79991ED9.png
PNG image data, 476 x 244, 8-bit/color RGB, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\826EFC38.png
PNG image data, 1268 x 540, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\8BBCBF4F.png
PNG image data, 399 x 605, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\A6AB76E0.emf
Windows Enhanced Metafile (EMF) image data version 0x10000
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\C7035FEE.emf
Windows Enhanced Metafile (EMF) image data version 0x10000
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\C83AFE53.png
PNG image data, 1686 x 725, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\D1A2B317.png
PNG image data, 476 x 244, 8-bit/color RGB, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\F5DD422C.png
PNG image data, 566 x 429, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\FB863104.jpeg
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 191x263, frames 3
dropped
clean
C:\Users\user\AppData\Roaming\CF97F5\5879F5.lck
very short file (no magic)
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-966771315-3019405637-367336477-1006\f554348b930ff81505ce47f7c6b7d232_ea860e7a-a87f-4a88-92ef-38f744458171
data
dropped
clean
There are 11 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
'C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE' -Embedding
malicious
C:\Users\Public\vbc.exe
'C:\Users\Public\vbc.exe'
malicious
C:\Users\Public\vbc.exe
C:\Users\Public\vbc.exe
malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
clean

URLs

Name
IP
Malicious
http://103.89.90.94/pzldoc/regasm.exe
103.89.90.94
malicious
http://kbfvzoboss.bid/alien/fre.php
malicious
http://alphastand.top/alien/fre.php
malicious
http://63.141.228.141/32.php/S4wFP8QBww9Tp
63.141.228.141
malicious
http://alphastand.win/alien/fre.php
malicious
http://alphastand.trade/alien/fre.php
malicious
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
http://www.day.com/dam/1.0
unknown
clean
http://www.ibsensoftware.com/
unknown
clean
http://www.%s.comPA
unknown
clean
https://github.com/georgw777/MediaManager
unknown
clean
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
unknown
clean
https://stackpath.bootstrapcdn.com/bootstrap/4.5.0/css/bootstrap.min.css
unknown
clean
https://github.com/georgw777/
unknown
clean
https://github.com/georgw777/MediaManager;https://github.com/georgw777/
unknown
clean
There are 5 hidden URLs, click here to show them.

IPs

IP
Domain
Country
Malicious
103.89.90.94
unknown
Viet Nam
malicious
63.141.228.141
unknown
United States
malicious

Registry

Path
Value
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
r~8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
MTTT
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ReviewToken
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EFEE8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
FontCachePath
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
VBAFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DefaultSheetR2L
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
UseSystemSeparators
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ThousandsSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
DecimalSeparator
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
|k8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F4E30
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F6191
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 21
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
LastPurgeTime
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EXCELFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F4E30
clean
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
EquationEditorFilesIntl_1033
clean
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
SavedLegacySettings
clean
There are 51 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
3369000
unkown
page read and write
malicious
400000
unkown
page execute and read and write
malicious
2381000
unkown
page read and write
malicious
AB000
unkown
page read and write
clean
170000
heap private
page read and write
clean
50E000
unkown
page read and write
clean
580000
unkown
page read and write
clean
6F0000
unkown
page read and write
clean
9D0000
unkown
page readonly
clean
450000
unkown
page read and write
clean
300000
heap private
page read and write
clean
320000
unkown
page read and write
clean
80000
unkown
page readonly
clean
1B0000
heap private
page read and write
clean
187000
unkown
page execute and read and write
clean
340000
unkown
page read and write
clean
16A000
unkown
page read and write
clean
610000
unkown
page read and write
clean
4F70000
heap private
page read and write
clean
580000
unkown
page read and write
clean
3E5B000
unkown
page read and write
clean
7EFDF000
unkown
page read and write
clean
8B7000
heap default
page read and write
clean
320000
unkown
page read and write
clean
810000
heap private
page execute and read and write
clean
4A40000
unkown
page read and write
clean
570000
unkown
page read and write
clean
8B0000
heap default
page read and write
clean
300000
unkown
page read and write
clean
2800000
unkown
page read and write
clean
590000
unkown
page read and write
clean
49B000
unkown
page execute and read and write
clean
23A8000
unkown
page read and write
clean
48C0000
unkown
page read and write
clean
197000
unkown
page execute and read and write
clean
140000
unkown
page read and write
clean
2DF000
unkown
page read and write
clean
47E0000
unkown
page readonly
clean
2A8000
unkown
page read and write
clean
870000
unkown
page readonly
clean
40E000
unkown
page read and write
clean
20000
unkown
page read and write
clean
450000
unkown
page read and write
clean
570000
unkown
page read and write
clean
300000
unkown
page read and write
clean
319000
heap private
page read and write
clean
D02000
unkown image
page execute read
clean
51C000
heap default
page read and write
clean
494000
heap default
page read and write
clean
C6D000
unkown
page read and write
clean
4B0000
unkown
page read and write
clean
D00000
unkown image
page readonly
clean
20000
unkown
page read and write
clean
340000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
2E0000
unkown
page execute and read and write
clean
2361000
unkown
page read and write
clean
30EE000
unkown
page read and write
clean
4F3D000
unkown
page read and write
clean
6E0000
unkown
page read and write
clean
170000
unkown
page read and write
clean
6F0000
unkown
page readonly
clean
610000
unkown
page read and write
clean
2630000
heap private
page read and write
clean
7EFDF000
unkown
page read and write
clean
49B2000
heap private
page read and write
clean
670000
heap default
page read and write
clean
610000
unkown
page execute and read and write
clean
BDF000
unkown
page read and write
clean
570000
unkown
page read and write
clean
AFAE000
unkown
page read and write
clean
4994000
heap private
page read and write
clean
124000
unkown
page read and write
clean
556E000
unkown
page read and write
clean
21C0000
unkown
page readonly
clean
310000
heap private
page read and write
clean
3361000
unkown
page read and write
clean
460000
unkown
page read and write
clean
6D0000
unkown
page read and write
clean
19B000
unkown
page execute and read and write
clean
620000
unkown
page read and write
clean
4BB0000
unkown
page readonly
clean
178000
heap private
page read and write
clean
680000
unkown
page read and write
clean
18A000
unkown
page execute and read and write
clean
620000
unkown
page read and write
clean
176000
unkown
page read and write
clean
305000
unkown
page read and write
clean
5230000
unkown
page read and write
clean
23AA000
unkown
page read and write
clean
8D4000
heap default
page read and write
clean
630000
heap private
page read and write
clean
536000
unkown
page read and write
clean
630000
heap private
page execute and read and write
clean
61F000
unkown
page read and write
clean
D00000
unkown image
page readonly
clean
770000
unkown
page read and write
clean
620000
unkown
page read and write
clean
750000
unkown
page read and write
clean
330000
unkown
page read and write
clean
470000
heap default
page read and write
clean
590000
unkown
page read and write
clean
2D0000
unkown
page read and write
clean
690000
unkown
page read and write
clean
570000
unkown
page read and write
clean
620000
unkown
page read and write
clean
7BE000
unkown
page read and write
clean
C70000
unkown
page readonly
clean
2320000
heap private
page read and write
clean
2813000
unkown
page read and write
clean
3642000
unkown
page read and write
clean
30D000
unkown
page read and write
clean
760000
unkown
page read and write
clean
6A0000
unkown
page read and write
clean
147000
unkown
page read and write
clean
D02000
unkown image
page execute read
clean
2FB0000
heap private
page read and write
clean
D00000
unkown image
page readonly
clean
610000
unkown
page read and write
clean
8F7000
heap default
page read and write
clean
22CE000
unkown
page read and write | page guard
clean
AE1E000
unkown
page read and write | page guard
clean
53A000
unkown
page read and write
clean
DBC000
unkown image
page readonly
clean
636000
heap private
page read and write
clean
410000
heap private
page execute and read and write
clean
6A0000
unkown
page read and write
clean
760000
unkown
page read and write
clean
30F0000
unkown
page read and write
clean
5131000
unkown
page read and write
clean
4B0000
unkown
page read and write
clean
4BC000
heap default
page read and write
clean
620000
unkown
page read and write
clean
300000
unkown
page read and write
clean
50B000
heap default
page read and write
clean
6A0000
unkown
page read and write
clean
DBC000
unkown image
page readonly
clean
740000
unkown
page read and write
clean
740000
unkown
page read and write
clean
620000
unkown
page read and write
clean
4FEE000
unkown
page read and write
clean
320000
unkown
page read and write
clean
4360000
unkown
page readonly
clean
6B0000
unkown
page read and write
clean
5193000
unkown
page read and write
clean
17D000
unkown
page execute and read and write
clean
22CF000
unkown
page read and write
clean
2E1F000
unkown
page read and write
clean
512E000
unkown
page read and write
clean
150000
unkown
page readonly
clean
26BF000
unkown
page read and write
clean
5130000
unkown
page read and write
clean
D00000
unkown image
page readonly
clean
578000
unkown
page read and write
clean
2900000
unkown
page readonly
clean
AE1F000
unkown
page read and write
clean
6A0000
unkown
page read and write
clean
160000
unkown
page read and write
clean
12D000
unkown
page execute and read and write
clean
477000
heap default
page read and write
clean
2E9000
unkown
page read and write
clean
498E000
unkown
page read and write
clean
6D0000
unkown
page read and write
clean
6C0000
heap private
page read and write
clean
464000
unkown
page read and write
clean
49D0000
unkown
page read and write
clean
620000
unkown
page read and write
clean
D02000
unkown image
page execute read
clean
123000
unkown
page execute and read and write
clean
850000
unkown
page readonly
clean
620000
unkown
page read and write
clean
2700000
unkown
page read and write
clean
6AA000
unkown
page read and write
clean
DBC000
unkown image
page readonly
clean
340000
unkown
page read and write
clean
B1BE000
unkown
page read and write
clean
110000
unkown
page read and write
clean
7FC000
unkown
page read and write
clean
570000
unkown
page read and write
clean
192000
unkown
page read and write
clean
CFF000
unkown
page read and write
clean
D00000
unkown image
page readonly
clean
610000
unkown
page read and write
clean
67E000
unkown
page read and write
clean
460000
unkown
page read and write
clean
47DF000
unkown
page read and write
clean
3577000
unkown
page read and write
clean
25BD000
unkown
page read and write
clean
670000
unkown
page read and write
clean
750000
unkown
page read and write
clean
52D000
unkown
page read and write
clean
D02000
unkown image
page execute read
clean
570000
unkown
page read and write
clean
468E000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
6AF000
unkown
page read and write
clean
4B0000
heap default
page read and write
clean
D00000
unkown image
page readonly
clean
73C000
unkown
page read and write
clean
524D000
unkown
page read and write
clean
350000
heap default
page read and write
clean
DBC000
unkown image
page readonly
clean
32F000
unkown
page read and write
clean
5A0000
unkown
page read and write
clean
2819000
unkown
page read and write
clean
59F000
unkown
page read and write
clean
4990000
heap private
page read and write
clean
C0000
unkown
page readonly
clean
4A0000
unkown
page execute and read and write
clean
60E000
unkown
page read and write
clean
4BAF000
unkown
page read and write
clean
6B0000
unkown
page read and write
clean
A812000
unkown
page read and write
clean
There are 203 hidden memdumps, click here to show them.