IOCReport

loading gif

Files

File Path
Type
Category
Malicious
Permission-1984690372-06252021.xlsm
Microsoft Excel 2007+
initial sample
malicious
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Permission-1984690372-06252021.xlsm.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Wed Sep 30 14:03:43 2020, mtime=Sat Jun 26 00:35:31 2021, atime=Sat Jun 26 00:35:31 2021, length=153172, window=hide
dropped
malicious
C:\Users\user\Desktop\~$Permission-1984690372-06252021.xlsm
data
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\61EBA0A8.jpg
[TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS6 (Windows), datetime=2021:02:11 21:11:18], baseline, precision 8, 1860x1000, frames 3
dropped
clean
C:\Users\user\AppData\Local\Temp\BC810000
data
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Desktop.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Read-Only, Directory, ctime=Thu Jun 27 16:19:49 2019, mtime=Sat Jun 26 00:35:31 2021, atime=Sat Jun 26 00:35:31 2021, length=8192, window=hide
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\Desktop\4D810000
data
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\94954BDE.jpg
[TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS6 (Windows), datetime=2021:02:11 21:11:18], baseline, precision 8, 1860x1000, frames 3
dropped
clean
C:\Users\user\AppData\Local\Temp\EBCE0000
data
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Permission-1984690372-06252021.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Wed Aug 26 14:08:13 2020, mtime=Sat Jun 26 00:28:37 2021, atime=Sat Jun 26 00:28:37 2021, length=153117, window=hide
dropped
clean
C:\Users\user\Desktop\7CCE0000
data
dropped
clean
There are 2 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding
malicious
C:\Windows\SysWOW64\regsvr32.exe
regsvr32 ..\Kro.fis
malicious
C:\Windows\SysWOW64\regsvr32.exe
regsvr32 ..\Kro.fis1
malicious
C:\Windows\SysWOW64\regsvr32.exe
regsvr32 ..\Kro.fis2
malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
malicious
C:\Windows\System32\regsvr32.exe
regsvr32 ..\Kro.fis
malicious
C:\Windows\System32\regsvr32.exe
regsvr32 ..\Kro.fis1
malicious
C:\Windows\System32\regsvr32.exe
regsvr32 ..\Kro.fis2
malicious

URLs

Name
IP
Malicious
http://190.14.37.3/44372.7746763889.dat
190.14.37.3
clean
http://185.183.99.120/44372.7746763889.dat
185.183.99.120
clean
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
unknown
clean
http://www.windows.com/pctv.
unknown
clean
http://investor.msn.com
unknown
clean
http://www.msnbc.com/news/ticker.txt
unknown
clean
http://www.icra.org/vocabulary/.
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
http://investor.msn.com/
unknown
clean
http://190.14.37.3/44372.7698814815.dat
190.14.37.3
clean
http://www.%s.comPA
unknown
clean
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
unknown
clean
http://www.hotmail.com/oe
unknown
clean
http://servername/isapibackend.dll
unknown
clean
http://185.183.99.120/44372.7698814815.dat
185.183.99.120
clean
There are 5 hidden URLs, click here to show them.

IPs

IP
Domain
Country
Malicious
190.14.37.3
unknown
Panama
clean
185.183.99.120
unknown
Netherlands
clean
185.240.103.219
unknown
Russian Federation
clean

Registry

Path
Value
Malicious
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
c21
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
d21
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
LastBootTime
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
ReviewToken
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
18549
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
VBAFiles
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
MSForms
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
MSComctlLib
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
18A98
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
18C1F
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
18D19
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
18DB5
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
ca1
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
271CC
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
273FE
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
ProductFiles
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
en-US
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
en-US
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
EXCELFiles
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
RoamingConfigurableSettings
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
RoamingLastSyncTime
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
RoamingLastWriteTime
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
CacheReady
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
LastRequest
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
CacheReady
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
LastUpdate
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
NextUpdate
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
SpellingAndGrammarFiles_1036
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
SpellingAndGrammarFiles_1033
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean
C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE
SpellingAndGrammarFiles_3082
clean