IOCReport

loading gif

Files

File Path
Type
Category
Malicious
INVOICE = 212888585 .xlsx
Microsoft Excel 2007+
initial sample
malicious
C:\Program Files (x86)\SMTP Service\smtpsvc.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Temp\tmp3811.tmp
XML 1.0 document, ASCII text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Roaming\ALP.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Users\user\AppData\Roaming\EA860E7A-A87F-4A88-92EF-38F744458171\run.dat
Non-ISO extended-ASCII text, with no line terminators
dropped
malicious
C:\Users\user\Desktop\~$INVOICE = 212888585 .xlsx
data
dropped
malicious
C:\Users\user\AppData\Local\Temp\tmp277F.tmp
XML 1.0 document, ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Roaming\EA860E7A-A87F-4A88-92EF-38F744458171\catalog.dat
data
dropped
clean
C:\Users\user\AppData\Roaming\EA860E7A-A87F-4A88-92EF-38F744458171\storage.dat
data
dropped
clean
C:\Users\user\AppData\Roaming\EA860E7A-A87F-4A88-92EF-38F744458171\task.dat
ASCII text, with no line terminators
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
'C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE' -Embedding
malicious
C:\Users\user\AppData\Roaming\ALP.exe
C:\Users\user\AppData\Roaming\ALP.exe
malicious
C:\Users\user\AppData\Roaming\ALP.exe
C:\Users\user\AppData\Roaming\ALP.exe
malicious
C:\Windows\SysWOW64\schtasks.exe
'schtasks.exe' /create /f /tn 'SMTP Service' /xml 'C:\Users\user\AppData\Local\Temp\tmp3811.tmp'
malicious
C:\Windows\SysWOW64\schtasks.exe
'schtasks.exe' /create /f /tn 'SMTP Service Task' /xml 'C:\Users\user\AppData\Local\Temp\tmp277F.tmp'
malicious
C:\Users\user\AppData\Roaming\ALP.exe
C:\Users\user\AppData\Roaming\ALP.exe 0
malicious
C:\Program Files (x86)\SMTP Service\smtpsvc.exe
'C:\Program Files (x86)\SMTP Service\smtpsvc.exe' 0
malicious
C:\Program Files (x86)\SMTP Service\smtpsvc.exe
'C:\Program Files (x86)\SMTP Service\smtpsvc.exe'
malicious
C:\Program Files (x86)\SMTP Service\smtpsvc.exe
C:\Program Files (x86)\SMTP Service\smtpsvc.exe
malicious
C:\Users\user\AppData\Roaming\ALP.exe
C:\Users\user\AppData\Roaming\ALP.exe
malicious
C:\Program Files (x86)\SMTP Service\smtpsvc.exe
C:\Program Files (x86)\SMTP Service\smtpsvc.exe
malicious
C:\Program Files (x86)\SMTP Service\smtpsvc.exe
C:\Program Files (x86)\SMTP Service\smtpsvc.exe
malicious
C:\Program Files (x86)\SMTP Service\smtpsvc.exe
C:\Program Files (x86)\SMTP Service\smtpsvc.exe
malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
clean
C:\Windows\System32\taskeng.exe
taskeng.exe {6D7D75E4-8EFD-44BB-96AC-FEA7E6E0852F} S-1-5-21-966771315-3019405637-367336477-1006:user-PC\user:Interactive:[1]
clean
There are 5 hidden processes, click here to show them.

URLs

Name
IP
Malicious
godisgood1.hopto.org
malicious
malicious
http://136.144.41.96/HHK.exe
136.144.41.96
malicious
http://www.%s.comPA
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
http://google.com
unknown
clean

Domains

Name
IP
Malicious
godisgood1.hopto.org
103.147.184.84
malicious

IPs

IP
Domain
Country
Malicious
103.147.184.84
godisgood1.hopto.org
unknown
malicious
136.144.41.96
unknown
Netherlands
malicious

Registry

Path
Value
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
$m'
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
MTTT
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
ReviewToken
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
30C7F
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
VBAFiles
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
dq'
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Max Display
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 1
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 2
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 3
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 4
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 5
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 6
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 7
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 8
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 9
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 10
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 11
clean
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Item 12
clean