IOC Report

loading gif

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
malicious
C:\Windows\System32\regsvr32.exe
'C:\Windows\System32\regsvr32.exe' C:\Datop\test.test
malicious
C:\Windows\System32\regsvr32.exe
'C:\Windows\System32\regsvr32.exe' C:\Datop\test1.test
malicious
C:\Windows\System32\regsvr32.exe
'C:\Windows\System32\regsvr32.exe' C:\Datop\test2.test
malicious

URLs

Name
IP
Malicious
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
unknown
clean
http://www.windows.com/pctv.
unknown
clean
http://investor.msn.com
unknown
clean
http://www.msnbc.com/news/ticker.txt
unknown
clean
https://ohemaa.org/HUVm9mDKLW9C/ocrafhh.html
172.93.99.178
clean
http://www.icra.org/vocabulary/.
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
https://madieandme.com.au/xnkpOLnvlN6T/ocrafh.html
101.0.112.4
clean
http://investor.msn.com/
unknown
clean
http://www.%s.comPA
unknown
clean
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
unknown
clean
http://www.hotmail.com/oe
unknown
clean
http://servername/isapibackend.dll
unknown
clean
https://amerident.com.do/xdOMlaB0XJ7/ocraf.html
108.179.242.179
clean
There are 4 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
ohemaa.org
172.93.99.178
clean
amerident.com.do
108.179.242.179
clean
madieandme.com.au
101.0.112.4
clean

IPs

IP
Domain
Country
Malicious
101.0.112.4
madieandme.com.au
Australia
clean
108.179.242.179
amerident.com.do
United States
clean
172.93.99.178
ohemaa.org
United States
clean

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
9'$
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel
MTTT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\2EE64
2EE64
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
VBAFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
,+$
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\MuiCache\151\52C64B7E
@%SystemRoot%\system32\qagentrt.dll,-10
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\MuiCache\151\52C64B7E
@%SystemRoot%\System32\fveui.dll,-843
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\MuiCache\151\52C64B7E
@%SystemRoot%\System32\fveui.dll,-844
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\MuiCache\151\52C64B7E
@%SystemRoot%\System32\wuaueng.dll,-400
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Place MRU
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 1
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 2
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 3
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 4
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 5
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 6
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 7
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 8
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 9
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 10
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 11
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 12
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 13
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 14
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 15
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 16
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 17
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 18
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 19
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 20
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\39E13
39E13
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Place MRU
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 1
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 2
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 3
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 4
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 5
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 6
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 7
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 8
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 9
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 10
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 11
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 12
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 13
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 14
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 15
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 16
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 17
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 18
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 19
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 20
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\39FC8
39FC8
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Security\Trusted Documents
LastPurgeTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
EXCELFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\12891DF7B048CD69D0196C8AD7A754C8A812A08C
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\12891DF7B048CD69D0196C8AD7A754C8A812A08C
Blob
clean
There are 59 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
2C6000
unkown
page read and write
clean
2A0000
unkown image
page readonly
clean
3FB9000
heap private
page read and write
clean
2C4000
unkown
page read and write
clean
2C5000
unkown
page read and write
clean
2C7000
heap default
page read and write
clean
27A000
heap default
page read and write
clean
80000
unkown image
page read and write
clean
324000
heap private
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
32A000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
2C4000
unkown
page read and write
clean
365000
unkown
page read and write
clean
342000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
3C0000
unkown
page read and write
clean
49E0000
unkown image
page readonly
clean
3F6000
unkown
page read and write
clean
730000
unkown image
page readonly
clean
190000
unkown
page execute and read and write
clean
364000
unkown
page read and write
clean
1A0000
unkown image
page readonly
clean
464000
heap private
page read and write
clean
4E6000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
206000
unkown
page read and write
clean
435000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
28E000
unkown
page read and write
clean
20A0000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
160000
unkown image
page read and write
clean
ABE000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
21AB000
heap private
page read and write
clean
374000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
456000
unkown
page read and write
clean
E0000
unkown image
page read and write
clean
43A000
unkown
page read and write
clean
356000
unkown
page read and write
clean
454000
unkown
page read and write
clean
4A0000
unkown
page read and write
clean
289000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
4030000
heap private
page read and write
clean
4BC7000
unkown image
page readonly
clean
170000
unkown
page read and write
clean
5D4000
heap private
page read and write
clean
460000
heap private
page read and write
clean
20000
unkown image
page readonly
clean
34C000
unkown
page read and write
clean
2E0000
heap default
page read and write
clean
30F000
unkown
page read and write
clean
3FB0000
heap private
page read and write
clean
315000
unkown
page read and write
clean
227000
heap default
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
730000
unkown image
page readonly
clean
4039000
heap private
page read and write
clean
454000
unkown
page read and write
clean
2205000
heap private
page read and write
clean
20000
heap private
page read and write
clean
470000
unkown
page read and write
clean
435000
unkown
page read and write
clean
3B5000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
70000
unkown image
page readonly
clean
4A27000
unkown image
page readonly
clean
2A0000
unkown
page execute and read and write
clean
3FB5000
heap private
page read and write
clean
590000
heap private
page read and write
clean
273000
heap default
page read and write
clean
3A50000
unkown image
page readonly
clean
223B000
heap private
page read and write
clean
3B0000
heap default
page read and write
clean
43C000
unkown
page read and write
clean
1D6000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
720000
unkown image
page readonly
clean
2175000
heap private
page read and write
clean
2080000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
3E90000
heap private
page read and write
clean
445000
unkown
page read and write
clean
1B0000
unkown
page read and write
clean
4A5000
unkown
page read and write
clean
1CC0000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
3E95000
heap private
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
2E7000
heap default
page read and write
clean
3E99000
heap private
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
2AA000
unkown
page read and write
clean
2AC000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
650000
heap private
page read and write
clean
2080000
heap private
page read and write
clean
30000
unkown image
page readonly
clean
D9000
unkown
page read and write
clean
1CC0000
unkown image
page readonly
clean
463000
unkown
page read and write
clean
2340000
unkown
page read and write
clean
2D4000
unkown
page read and write
clean
F0000
unkown
page read and write
clean
3B0000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
25E000
heap default
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
1A0000
unkown
page read and write
clean
355000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
21DF000
unkown
page read and write
clean
364000
unkown
page read and write
clean
41A000
unkown
page read and write
clean
5A0000
unkown image
page readonly
clean
1CD000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
3AF000
unkown
page read and write
clean
366000
unkown
page read and write
clean
594000
heap private
page read and write
clean
40A000
heap default
page read and write
clean
2100000
unkown image
page readonly
clean
100000
unkown
page read and write
clean
455000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
5A0000
unkown image
page readonly
clean
2FE000
heap default
page read and write
clean
31D000
heap default
page read and write
clean
2A2000
unkown
page read and write
clean
2B5000
unkown
page read and write
clean
4A6000
unkown
page read and write
clean
290000
unkown
page execute and read and write
clean
23EF000
unkown
page read and write
clean
4B47000
unkown image
page readonly
clean
464000
unkown
page read and write
clean
1D80000
unkown image
page readonly
clean
32B000
heap default
page read and write
clean
2D3000
unkown
page read and write
clean
21F0000
unkown
page read and write
clean
3B40000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
57F000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
345000
unkown
page read and write
clean
4960000
unkown image
page readonly
clean
240F000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
1D0000
unkown
page read and write
clean
2B0000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
21E0000
unkown
page read and write
clean
2200000
heap private
page read and write
clean
30000
unkown image
page readonly
clean
90000
unkown
page read and write
clean
355000
unkown
page read and write
clean
31A000
heap default
page read and write
clean
34A000
unkown
page read and write
clean
326000
heap default
page read and write
clean
7E0000
unkown image
page readonly
clean
654000
heap private
page read and write
clean
32E000
unkown
page read and write
clean
594000
heap private
page read and write
clean
24000
heap private
page read and write
clean
345000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
2085000
heap private
page read and write
clean
10000
unkown image
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
403000
heap default
page read and write
clean
7F0000
unkown image
page readonly
clean
4035000
heap private
page read and write
clean
10000
unkown image
page read and write
clean
320000
heap private
page read and write
clean
3B7000
heap default
page read and write
clean
310000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
2B5000
unkown
page read and write
clean
373000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
1FC0000
unkown image
page readonly
clean
3A40000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
590000
heap private
page read and write
clean
41E000
unkown
page read and write
clean
720000
unkown image
page readonly
clean
9AF000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
320000
unkown
page read and write
clean
660000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
5D0000
heap private
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
4B0000
unkown
page read and write
clean
454000
unkown
page read and write
clean
2C4000
unkown
page read and write
clean
136000
unkown
page read and write
clean
2C0000
heap default
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
3EE000
heap default
page read and write
clean
2A5000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
364000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
20BB000
heap private
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
220000
heap default
page read and write
clean
2170000
heap private
page read and write
clean
313000
heap default
page read and write
clean
445000
unkown
page read and write
clean
2B0000
unkown
page read and write
clean
129000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
28A000
unkown
page read and write
clean
2A5000
unkown
page read and write
clean
49F000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
432000
unkown
page read and write
clean
4840000
unkown image
page readonly
clean
There are 224 hidden memdumps, click here to show them.