IOC Report

loading gif

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
malicious
C:\Windows\System32\regsvr32.exe
'C:\Windows\System32\regsvr32.exe' C:\Datop\test.test
malicious
C:\Windows\System32\regsvr32.exe
'C:\Windows\System32\regsvr32.exe' C:\Datop\test1.test
malicious
C:\Windows\System32\regsvr32.exe
'C:\Windows\System32\regsvr32.exe' C:\Datop\test2.test
malicious

URLs

Name
IP
Malicious
https://mercanets.com/9DPZqAfZdq5z/key.xml
162.222.225.250
malicious
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
unknown
clean
http://www.windows.com/pctv.
unknown
clean
https://geit.in/MeOlE9Xxd/key.xml
162.251.80.22
clean
http://investor.msn.com
unknown
clean
http://www.msnbc.com/news/ticker.txt
unknown
clean
http://www.icra.org/vocabulary/.
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
https://gillcart.com/Cdpmoyhr/key.xml
199.79.63.251
clean
http://investor.msn.com/
unknown
clean
http://www.%s.comPA
unknown
clean
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
unknown
clean
http://www.hotmail.com/oe
unknown
clean
http://servername/isapibackend.dll
unknown
clean
There are 4 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
mercanets.com
162.222.225.250
clean
geit.in
162.251.80.22
clean
gillcart.com
199.79.63.251
clean

IPs

IP
Domain
Country
Malicious
199.79.63.251
gillcart.com
United States
clean
162.251.80.22
geit.in
United States
clean
162.222.225.250
mercanets.com
United States
clean

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
o4-
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel
MTTT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\2CF50
2CF50
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
VBAFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
:8-
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\MuiCache\151\52C64B7E
@%SystemRoot%\system32\qagentrt.dll,-10
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\MuiCache\151\52C64B7E
@%SystemRoot%\System32\fveui.dll,-843
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\MuiCache\151\52C64B7E
@%SystemRoot%\System32\fveui.dll,-844
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\MuiCache\151\52C64B7E
@%SystemRoot%\System32\wuaueng.dll,-400
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
ProductNonBootFilesIntl_1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Place MRU
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 1
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 2
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 3
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 4
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 5
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 6
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 7
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 8
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 9
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 10
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 11
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 12
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 13
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 14
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 15
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 16
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 17
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 18
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 19
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 20
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\39E04
39E04
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Place MRU
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 1
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 2
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 3
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 4
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 5
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 6
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 7
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 8
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 9
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 10
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 11
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 12
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 13
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 14
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 15
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 16
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 17
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 18
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 19
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 20
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\39F6A
39F6A
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Security\Trusted Documents
LastPurgeTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
EXCELFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\12891DF7B048CD69D0196C8AD7A754C8A812A08C
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\12891DF7B048CD69D0196C8AD7A754C8A812A08C
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
ProductNonBootFilesIntl_1033
clean
There are 61 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
7FFFFFC0000
unkown image
page readonly
clean
190000
unkown
page execute and read and write
clean
204000
heap private
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
11E000
heap default
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
165000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
82E000
unkown
page read and write
clean
435000
unkown
page read and write
clean
237000
heap default
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
E7000
heap default
page read and write
clean
10000
unkown image
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
48F000
unkown
page read and write
clean
22DF000
unkown
page read and write
clean
466000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
4850000
unkown image
page readonly
clean
830000
unkown image
page readonly
clean
16C000
unkown
page read and write
clean
40E000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
E0000
heap default
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
3FC5000
heap private
page read and write
clean
30000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
4DF000
unkown
page read and write
clean
420000
heap private
page read and write
clean
5A0000
unkown image
page readonly
clean
200000
heap private
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
1F0000
unkown
page read and write
clean
2B5000
unkown
page read and write
clean
435000
unkown
page read and write
clean
3A7000
heap default
page read and write
clean
2D6000
unkown
page read and write
clean
26E000
heap default
page read and write
clean
120000
unkown
page execute and read and write
clean
30000
unkown image
page readonly
clean
1E0000
unkown image
page read and write
clean
6A0000
unkown image
page readonly
clean
1DC0000
unkown image
page readonly
clean
100000
unkown
page read and write
clean
229F000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
13A000
heap default
page read and write
clean
370000
heap private
page read and write
clean
175000
unkown
page read and write
clean
396000
unkown
page read and write
clean
186000
unkown
page read and write
clean
133000
heap default
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
444000
unkown
page read and write
clean
466000
unkown
page read and write
clean
2BC000
unkown
page read and write
clean
2A0000
unkown
page execute and read and write
clean
30000
unkown image
page readonly
clean
1D5000
unkown
page read and write
clean
424000
heap private
page read and write
clean
2E3000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
2B5000
unkown
page read and write
clean
24000
heap private
page read and write
clean
7EFE0000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
283000
heap default
page read and write
clean
3AB000
heap private
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
330000
unkown
page read and write
clean
28A000
heap default
page read and write
clean
175000
unkown
page read and write
clean
4A0000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
200000
heap private
page read and write
clean
530000
unkown image
page readonly
clean
20A0000
heap private
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
40000
unkown image
page readonly
clean
3FE0000
heap private
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
6C0000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
3FA000
heap default
page read and write
clean
BEF000
unkown
page read and write
clean
20000
unkown image
page readonly
clean
193000
unkown
page read and write
clean
325000
unkown
page read and write
clean
42C000
unkown
page read and write
clean
300000
heap private
page read and write
clean
4A37000
unkown image
page readonly
clean
1AD000
unkown
page read and write
clean
20000
unkown image
page readonly
clean
690000
heap private
page read and write
clean
2B2000
unkown
page read and write
clean
1CF000
unkown
page read and write
clean
40A000
unkown
page read and write
clean
31F000
unkown
page read and write
clean
3FC9000
heap private
page read and write
clean
33B000
heap private
page read and write
clean
22D0000
unkown
page read and write
clean
2BA000
unkown
page read and write
clean
7C0000
unkown image
page readonly
clean
2D4000
unkown
page read and write
clean
165000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
454000
unkown
page read and write
clean
4970000
unkown image
page readonly
clean
7B0000
unkown image
page readonly
clean
3A10000
unkown image
page readonly
clean
16A000
unkown
page read and write
clean
444000
unkown
page read and write
clean
3FC0000
heap private
page read and write
clean
22B0000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
2A6000
heap default
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
324000
heap private
page read and write
clean
1B0000
unkown
page read and write
clean
236000
unkown
page read and write
clean
6B0000
unkown image
page readonly
clean
4990000
unkown image
page readonly
clean
3EA5000
heap private
page read and write
clean
3FE5000
heap private
page read and write
clean
1D0000
unkown
page read and write
clean
F9000
unkown
page read and write
clean
366000
unkown
page read and write
clean
530000
unkown
page read and write
clean
260000
heap default
page read and write
clean
7EFE0000
unkown image
page readonly
clean
3ECE000
unkown
page read and write
clean
E0000
unkown image
page readonly
clean
2C5000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
70000
unkown image
page read and write
clean
630000
unkown image
page readonly
clean
2AB000
heap default
page read and write
clean
1A0000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
3DE000
heap default
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
566000
unkown
page read and write
clean
320000
heap private
page read and write
clean
1D50000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
2B0000
unkown image
page readonly
clean
224000
heap private
page read and write
clean
162000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
425000
unkown
page read and write
clean
2C0000
unkown
page read and write
clean
184000
unkown
page read and write
clean
2050000
unkown image
page readonly
clean
2D4000
unkown
page read and write
clean
430000
unkown
page read and write
clean
444000
unkown
page read and write
clean
22E0000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
74F000
unkown
page read and write
clean
360000
unkown
page read and write
clean
267000
heap default
page read and write
clean
220000
heap private
page read and write
clean
39E0000
unkown image
page readonly
clean
14A000
unkown
page read and write
clean
204000
heap private
page read and write
clean
1F9000
unkown
page read and write
clean
2D5000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
20DB000
heap private
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
184000
unkown
page read and write
clean
29A000
unkown
page read and write
clean
170000
unkown
page read and write
clean
445000
unkown
page read and write
clean
140000
unkown
page read and write
clean
425000
unkown
page read and write
clean
375000
heap private
page read and write
clean
130000
unkown image
page readonly
clean
4B77000
unkown image
page readonly
clean
14E000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
495000
unkown
page read and write
clean
4D6000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
29D000
heap default
page read and write
clean
694000
heap private
page read and write
clean
20000
heap private
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
2D4000
unkown
page read and write
clean
3EA0000
heap private
page read and write
clean
3FE9000
heap private
page read and write
clean
200000
unkown
page read and write
clean
42A000
unkown
page read and write
clean
305000
heap private
page read and write
clean
422000
unkown
page read and write
clean
1F50000
unkown image
page readonly
clean
299000
unkown
page read and write
clean
194000
unkown
page read and write
clean
3A00000
unkown image
page readonly
clean
446000
unkown
page read and write
clean
1C50000
unkown image
page readonly
clean
453000
unkown
page read and write
clean
820000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
320000
unkown
page read and write
clean
F0000
unkown image
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
185000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
2C5000
unkown
page read and write
clean
184000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
3EA9000
heap private
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
2E4000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
3A0000
heap default
page read and write
clean
490000
unkown
page read and write
clean
430000
unkown
page read and write
clean
230000
heap default
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
20A5000
heap private
page read and write
clean
10000
unkown image
page read and write
clean
3F3000
heap default
page read and write
clean
4B57000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
29E000
unkown
page read and write
clean
There are 225 hidden memdumps, click here to show them.