IOCReport

loading gif

Files

File Path
Type
Category
Malicious
4TWEQh2HJb.xls
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, Code page: 1252, Title: Invoice 720710 from Quickbooks, LLC, Author: Quickbooks, LLC, Last Saved By: user, Name of Creating Application: Microsoft Excel, Create Time/Date: Wed Jul 14 09:38:23 2021, Last Saved Time/Date: Wed Jul 14 15:06:14 2021, Security: 0
initial sample
malicious
C:\ProgramData\qDialogMainChartType.exe
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\ProgramData\qRangeAutoFormatLocalFormat3.sct
HTML document, ASCII text, with very long lines, with CRLF line terminators
dropped
malicious

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
malicious
C:\Windows\System32\mshta.exe
mshta 'C:\ProgramData\qRangeAutoFormatLocalFormat3.sct'
malicious
C:\ProgramData\qDialogMainChartType.exe
C:\ProgramData\qDialogMainChartType.exe
malicious

URLs

Name
IP
Malicious
http://fontfabrik.comQ
unknown
clean
http://www.msnbc.com/news/ticker.txt
unknown
clean
http://onlinefastsolutions.com:8088/images/details.bin
unknown
clean
http://www.tiro.com;Copyright
unknown
clean
http://www.fontbureau.com/designers?
unknown
clean
http://insiderushings.com:8088/js/file13.binj
unknown
clean
http://paymentadvisry.com:8088/wp-theme/file7.bin3.sct
unknown
clean
http://onlinefastsolutions.com:8088/js/file1.bin
unknown
clean
http://www.ncst.ernet.in/~rkjoshi
unknown
clean
http://www.typography.netD
unknown
clean
http://www.galapagosdesign.com/staff/dennis.htm
unknown
clean
http://www.icra.org/vocabulary/.
unknown
clean
http://onlinefastsolutions.com:8088/images/file13.bin
unknown
clean
http://onlinefastsolutions.com:8088/tpls/file3.bind
unknown
clean
http://onlinefastsolutions.com:8088/tpls/file3.binc
unknown
clean
http://investor.msn.com/
unknown
clean
http://buyer-remindment.com:8088/fonts/file8.bin
unknown
clean
http://www.%s.comPA
unknown
clean
http://www.fonts.com
unknown
clean
http://www.sandoll.co.kr
unknown
clean
http://onlinefastsolutions.com:8088/tpls/file3.binQ
unknown
clean
http://www.urwpp.de
unknown
clean
http://www.zhongyicts.com.cn
unknown
clean
http://www.sakkal.com
unknown
clean
http://onlinefastsolutions.com:8088/tpls/file3.binX
unknown
clean
http://www.bethmardutho.org.P
unknown
clean
http://insiderushings.com:8088/js/file13.bin
unknown
clean
http://www.windows.com/pctv.
unknown
clean
http://investor.msn.com
unknown
clean
http://www.fontbureau.com
unknown
clean
http://www.galapagosdesign.com/
unknown
clean
http://www.ascendercorp.com/
unknown
clean
http://fasteasyupdates.com:8088/vendors/file4.bin
unknown
clean
http://www.c-and-g.co.jp
unknown
clean
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
unknown
clean
http://www.hotmail.com/oe
unknown
clean
http://paymentadvisry.com:8088/wp-theme/file7.bin
unknown
clean
http://buyer-remindment.com:8088/tpls/file4.bin
unknown
clean
http://onlinefastsolutions.com:8088/js/file1.binT
unknown
clean
http://onlinefastsolutions.com:8088/images/details.binG
unknown
clean
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
unknown
clean
http://www.founder.com.cn/cn/
unknown
clean
http://www.fontbureau.com/designers/cabarga.htmlN
unknown
clean
http://www.founder.com.cn/cn
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
http://www.fontbureau.com/designers/frere-jones.html
unknown
clean
http://onlinefastsolutions.com:8088/tpls/file3.bin
208.83.69.35
clean
http://www.ascendercorp.com/typedesigners.htmlt
unknown
clean
http://buyer-remindment.com:8088/tpls/file4.bin:
unknown
clean
http://buyer-remindment.com:8088/css/file7.bin
unknown
clean
http://www.fontbureau.com/designers/
unknown
clean
There are 41 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
onlinefastsolutions.com
208.83.69.35
clean

IPs

IP
Domain
Country
Malicious
78.46.78.42
unknown
Germany
malicious
202.29.60.34
unknown
Thailand
malicious
66.175.217.172
unknown
United States
malicious
208.83.69.35
onlinefastsolutions.com
United States
clean

Registry

Path
Value
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
<~9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
MTTT
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
VBAFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ReviewToken
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EEEE1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
8f9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F51C8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 13
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 14
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 15
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 16
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 17
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 18
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 19
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 20
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
F68D1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
LastPurgeTime
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
1033
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
EXCELFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ProductFiles
clean
There are 47 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
10001000
unkown image
page execute read
malicious
4D4C000
unkown
page read and write
clean
D0000
heap default
page read and write
clean
45D5000
unkown
page readonly
clean
4536000
unkown
page readonly
clean
2470000
unkown
page readonly
clean
4542000
unkown
page readonly
clean
2390000
unkown
page read and write
clean
2495000
heap private
page read and write
clean
5830000
heap private
page read and write
clean
370000
heap default
page read and write
clean
10000000
unkown image
page readonly
clean
4D5B000
unkown
page read and write
clean
7DF60000
unkown
page read and write
clean
25A4000
unkown
page read and write
clean
2570000
unkown
page read and write
clean
279B000
heap private
page read and write
clean
1D10000
unkown
page readonly
clean
53F0000
heap private
page read and write
clean
546000
heap private
page read and write
clean
4F0000
heap private
page read and write
clean
2720000
unkown
page readonly
clean
2540000
unkown
page read and write
clean
259C000
unkown
page read and write
clean
7DE80000
unkown
page read and write
clean
1F4000
heap private
page read and write
clean
1FA000
heap private
page read and write
clean
2440000
unkown
page readonly
clean
44F5000
unkown
page readonly
clean
4DA0000
unkown
page read and write
clean
47D0000
unkown
page readonly
clean
4D76000
unkown
page read and write
clean
3B4000
unkown
page read and write
clean
362000
unkown
page read and write
clean
3F00000
unkown
page readonly
clean
25A8000
unkown
page read and write
clean
4506000
unkown
page readonly
clean
4D5C000
unkown
page read and write
clean
251C000
unkown
page read and write
clean
7EFDF000
unkown
page read and write
clean
4D00000
unkown
page read and write
clean
2B00000
heap private
page read and write
clean
258C000
unkown
page read and write
clean
4D70000
unkown
page read and write
clean
4D5E000
unkown
page read and write
clean
4D59000
unkown
page read and write
clean
4482000
unkown
page readonly
clean
4444000
unkown
page readonly
clean
4772000
unkown
page readonly
clean
394000
unkown
page read and write
clean
24B2000
heap private
page read and write
clean
220000
unkown
page readonly
clean
25B4000
unkown
page read and write
clean
7DFE0000
unkown
page read and write
clean
22C0000
unkown
page read and write
clean
1BF000
heap default
page read and write
clean
4484000
unkown
page readonly
clean
4D59000
unkown
page read and write
clean
24D0000
unkown
page read and write
clean
49F0000
unkown
page write copy
clean
3E65000
heap private
page read and write
clean
4C0B000
heap private
page read and write
clean
2534000
unkown
page read and write
clean
4288000
unkown
page readonly
clean
DE0000
unkown
page readonly
clean
44B2000
unkown
page readonly
clean
2100000
unkown
page read and write
clean
377000
heap default
page read and write
clean
44D6000
unkown
page readonly
clean
D7000
heap default
page read and write
clean
2550000
unkown
page read and write
clean
7DF71000
unkown
page read and write
clean
7DF80000
unkown
page read and write
clean
23A0000
unkown
page write copy
clean
25C0000
unkown
page read and write
clean
359000
unkown
page read and write
clean
10000000
unkown image
page readonly
clean
25C4000
unkown
page read and write
clean
45E9000
unkown
page readonly
clean
5510000
unkown
page read and write
clean
47B0000
unkown
page readonly
clean
1B0000
unkown
page readonly
clean
39E0000
unkown
page readonly
clean
8C000
unkown
page read and write
clean
250C000
unkown
page read and write
clean
4D64000
unkown
page read and write
clean
2D0000
unkown
page read and write
clean
60000
unkown
page readonly
clean
25A0000
unkown
page read and write
clean
306D000
unkown
page read and write
clean
1001A000
unkown image
page readonly
clean
2430000
unkown
page readonly
clean
582F000
unkown
page read and write
clean
45A5000
unkown
page readonly
clean
4555000
unkown
page readonly
clean
3EE0000
unkown
page readonly
clean
2480000
heap private
page read and write
clean
4D59000
unkown
page read and write
clean
10016000
unkown image
page write copy
clean
4970000
heap private
page read and write
clean
2578000
unkown
page read and write
clean
3AF000
unkown
page read and write
clean
45E2000
unkown
page readonly
clean
4589000
unkown
page readonly
clean
1C9000
heap default
page read and write
clean
2580000
unkown
page read and write
clean
346000
unkown
page read and write
clean
2490000
heap private
page read and write
clean
394000
heap default
page read and write
clean
44E2000
unkown
page readonly
clean
4D6B000
unkown
page read and write
clean
4582000
unkown
page readonly
clean
1D00000
heap private
page read and write
clean
2569000
unkown
page read and write
clean
2730000
unkown
page readonly
clean
2548000
unkown
page read and write
clean
6B62000
unkown
page read and write
clean
4569000
unkown
page readonly
clean
2554000
unkown
page read and write
clean
4DAB000
unkown
page read and write
clean
4462000
unkown
page readonly
clean
4D8A000
unkown
page read and write
clean
211D000
unkown
page read and write
clean
C60000
unkown
page readonly
clean
25B0000
unkown
page read and write
clean
4C80000
heap private
page read and write
clean
10E000
heap default
page read and write
clean
3B3000
unkown
page read and write
clean
2B05000
heap private
page read and write
clean
4E90000
heap private
page read and write
clean
4B30000
heap private
page read and write
clean
4BD0000
heap private
page read and write
clean
4566000
unkown
page readonly
clean
1F0000
heap private
page read and write
clean
325B000
unkown
page read and write
clean
4880000
heap private
page read and write
clean
250000
heap default
page read and write
clean
4D74000
unkown
page read and write
clean
540000
heap private
page read and write
clean
4282000
unkown
page readonly
clean
2530000
unkown
page read and write
clean
10000000
unkown image
page readonly
clean
25AA000
unkown
page read and write
clean
6D0000
unkown
page readonly
clean
2C8E000
unkown
page read and write
clean
2D00000
unkown
page read and write
clean
4D8F000
unkown
page read and write
clean
3600000
unkown
page readonly
clean
4D79000
unkown
page read and write
clean
4464000
unkown
page readonly
clean
4512000
unkown
page readonly
clean
239D000
unkown
page read and write
clean
44C5000
unkown
page readonly
clean
37D000
unkown
page read and write
clean
2510000
unkown
page read and write
clean
10015000
unkown image
page readonly
clean
350000
unkown
page read and write
clean
2760000
heap private
page read and write
clean
4605000
unkown
page readonly
clean
10001000
unkown image
page execute read
clean
7DF77000
unkown
page read and write
clean
16F000
heap default
page read and write
clean
2528000
unkown
page read and write
clean
6F52000
unkown
page readonly
clean
5610000
heap private
page read and write
clean
1FD000
heap private
page read and write
clean
2524000
unkown
page read and write
clean
2508000
unkown
page read and write
clean
25C8000
unkown
page read and write
clean
3E69000
heap private
page read and write
clean
F80000
unkown
page readonly
clean
346F000
unkown
page read and write
clean
456D000
unkown
page readonly
clean
5B3E000
unkown
page read and write
clean
3470000
unkown
page readonly
clean
2484000
heap private
page read and write
clean
4525000
unkown
page readonly
clean
27E0000
unkown
page readonly
clean
306000
unkown
page read and write
clean
2730000
unkown
page read and write
clean
45B9000
unkown
page readonly
clean
2600000
unkown
page readonly
clean
310000
unkown
page read and write
clean
4D0A000
unkown
page read and write
clean
18E000
unkown
page read and write
clean
398000
unkown
page read and write
clean
5490000
heap private
page read and write
clean
37E7000
unkown
page readonly
clean
2538000
unkown
page read and write
clean
1001D000
unkown image
page read and write
clean
1001F000
unkown image
page readonly
clean
254C000
unkown
page read and write
clean
22C0000
unkown
page read and write
clean
4D7B000
unkown
page read and write
clean
2EFF000
unkown
page read and write
clean
4442000
unkown
page readonly
clean
240000
unkown
page execute and read and write
clean
20000
unkown
page read and write
clean
2730000
unkown
page read and write
clean
2380000
unkown
page readonly
clean
7DF74000
unkown
page read and write
clean
23F0000
unkown
page read and write
clean
26E0000
unkown
page read and write
clean
870000
unkown
page readonly
clean
4F10000
unkown
page read and write
clean
5B44000
unkown
page readonly
clean
2520000
unkown
page read and write
clean
4D61000
unkown
page read and write
clean
5310000
unkown
page readonly
clean
2CFE000
unkown
page read and write
clean
2544000
unkown
page read and write
clean
4382000
unkown
page readonly
clean
7DE70000
unkown
page read and write
clean
2765000
heap private
page read and write
clean
3E60000
heap private
page read and write
clean
4D72000
unkown
page read and write
clean
230000
unkown
page read and write
clean
2588000
unkown
page read and write
clean
2518000
unkown
page read and write
clean
4BD4000
heap private
page read and write
clean
23B0000
unkown
page read and write
clean
3AF000
unkown
page read and write
clean
257C000
unkown
page read and write
clean
5623000
heap private
page read and write
clean
25AD000
unkown
page read and write
clean
30C0000
heap private
page read and write
clean
252C000
unkown
page read and write
clean
4D88000
unkown
page read and write
clean
2559000
unkown
page read and write
clean
239A000
unkown
page read and write
clean
4D5E000
unkown
page read and write
clean
4D82000
unkown
page read and write
clean
550000
unkown
page readonly
clean
19A000
heap default
page read and write
clean
59AF000
unkown
page read and write
clean
10028000
unkown image
page readonly
clean
45B2000
unkown
page readonly
clean
47F0000
unkown
page readonly
clean
There are 228 hidden memdumps, click here to show them.