IOC Report

loading gif

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
malicious
C:\Windows\System32\regsvr32.exe
'C:\Windows\System32\regsvr32.exe' C:\Datop\test.test
malicious
C:\Windows\System32\regsvr32.exe
'C:\Windows\System32\regsvr32.exe' C:\Datop\test1.test
malicious
C:\Windows\System32\regsvr32.exe
'C:\Windows\System32\regsvr32.exe' C:\Datop\test2.test
malicious

URLs

Name
IP
Malicious
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
unknown
clean
http://www.windows.com/pctv.
unknown
clean
http://investor.msn.com
unknown
clean
http://www.msnbc.com/news/ticker.txt
unknown
clean
https://ohemaa.org/HUVm9mDKLW9C/ocrafhh.html
172.93.99.178
clean
http://www.icra.org/vocabulary/.
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
https://madieandme.com.au/xnkpOLnvlN6T/ocrafh.html
101.0.112.4
clean
http://investor.msn.com/
unknown
clean
http://www.%s.comPA
unknown
clean
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
unknown
clean
http://www.hotmail.com/oe
unknown
clean
http://servername/isapibackend.dll
unknown
clean
https://amerident.com.do/xdOMlaB0XJ7/ocraf.html
108.179.242.179
clean
There are 4 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
ohemaa.org
172.93.99.178
clean
amerident.com.do
108.179.242.179
clean
madieandme.com.au
101.0.112.4
clean

IPs

IP
Domain
Country
Malicious
101.0.112.4
madieandme.com.au
Australia
clean
108.179.242.179
amerident.com.do
United States
clean
172.93.99.178
ohemaa.org
United States
clean

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
v:*
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel
MTTT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\30973
30973
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
VBAFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
i>*
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\MuiCache\151\52C64B7E
@%SystemRoot%\system32\qagentrt.dll,-10
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\MuiCache\151\52C64B7E
@%SystemRoot%\System32\fveui.dll,-843
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\MuiCache\151\52C64B7E
@%SystemRoot%\System32\fveui.dll,-844
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\MuiCache\151\52C64B7E
@%SystemRoot%\System32\wuaueng.dll,-400
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Place MRU
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 1
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 2
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 3
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 4
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 5
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 6
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 7
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 8
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 9
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 10
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 11
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 12
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 13
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 14
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 15
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 16
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 17
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 18
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 19
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 20
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\39C4F
39C4F
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Place MRU
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 1
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 2
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 3
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 4
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 5
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 6
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 7
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 8
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 9
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 10
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 11
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 12
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 13
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 14
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 15
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 16
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 17
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 18
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 19
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 20
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\39E42
39E42
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Security\Trusted Documents
LastPurgeTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
EXCELFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\12891DF7B048CD69D0196C8AD7A754C8A812A08C
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\12891DF7B048CD69D0196C8AD7A754C8A812A08C
Blob
clean
There are 59 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
2EE000
unkown
page read and write
clean
3C4000
unkown
page read and write
clean
5E0000
heap private
page read and write
clean
1FA0000
unkown image
page readonly
clean
1CA0000
unkown image
page readonly
clean
3C0000
unkown
page read and write
clean
375000
unkown
page read and write
clean
305000
unkown
page read and write
clean
270000
unkown
page read and write
clean
3F45000
heap private
page read and write
clean
10000
unkown image
page read and write
clean
236000
unkown
page read and write
clean
1A0000
unkown image
page readonly
clean
4B0000
heap private
page read and write
clean
574000
heap private
page read and write
clean
170000
unkown
page read and write
clean
3B5000
unkown
page read and write
clean
3A40000
unkown image
page readonly
clean
2D0000
heap default
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
287000
heap default
page read and write
clean
374000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
700000
unkown image
page readonly
clean
35E000
heap default
page read and write
clean
1A6000
unkown
page read and write
clean
C0000
unkown image
page readonly
clean
4C0000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
2A0000
unkown image
page readonly
clean
159000
unkown
page read and write
clean
20C0000
heap private
page read and write
clean
35A000
unkown
page read and write
clean
160000
unkown image
page read and write
clean
3C4000
unkown
page read and write
clean
3FF5000
heap private
page read and write
clean
160000
unkown image
page read and write
clean
21A5000
heap private
page read and write
clean
40000
unkown image
page readonly
clean
38A000
unkown
page read and write
clean
280000
heap default
page read and write
clean
2D3000
heap default
page read and write
clean
2BE000
heap default
page read and write
clean
490000
unkown
page execute and read and write
clean
3A2000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
F9000
unkown
page read and write
clean
600000
unkown image
page readonly
clean
4960000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
370000
unkown
page read and write
clean
365000
unkown
page read and write
clean
324000
unkown
page read and write
clean
B9000
unkown
page read and write
clean
3C6000
unkown
page read and write
clean
3C4000
unkown
page read and write
clean
3F1F000
unkown
page read and write
clean
21A0000
heap private
page read and write
clean
780000
unkown image
page readonly
clean
170000
unkown
page read and write
clean
190000
unkown
page execute and read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
290000
unkown
page execute and read and write
clean
1B0000
unkown
page read and write
clean
352000
unkown
page read and write
clean
2DA000
heap default
page read and write
clean
30C000
unkown
page read and write
clean
37A000
heap default
page read and write
clean
3FB9000
heap private
page read and write
clean
170000
unkown
page read and write
clean
560000
heap private
page read and write
clean
4F4000
heap private
page read and write
clean
305000
unkown
page read and write
clean
325000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
406000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
3C5000
unkown
page read and write
clean
355000
unkown
page read and write
clean
790000
unkown image
page readonly
clean
3D4000
unkown
page read and write
clean
30A000
unkown
page read and write
clean
36F000
unkown
page read and write
clean
3F40000
heap private
page read and write
clean
302000
unkown
page read and write
clean
324000
unkown
page read and write
clean
3FB0000
heap private
page read and write
clean
383000
unkown
page read and write
clean
323000
heap default
page read and write
clean
1F0000
heap private
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
2270000
unkown
page read and write
clean
20000
unkown image
page readonly
clean
3FF0000
heap private
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
30E000
heap default
page read and write
clean
180000
unkown
page read and write
clean
222B000
heap private
page read and write
clean
21F0000
heap private
page read and write
clean
3F49000
heap private
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
5A0000
unkown
page read and write
clean
33A000
unkown
page read and write
clean
3A5000
unkown
page read and write
clean
4D0000
unkown
page read and write
clean
3D0000
unkown
page read and write
clean
32A000
heap default
page read and write
clean
4AD7000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
40000
unkown image
page readonly
clean
780000
unkown image
page readonly
clean
376000
unkown
page read and write
clean
3B6000
unkown
page read and write
clean
410000
unkown
page read and write
clean
4F0000
heap private
page read and write
clean
536000
unkown
page read and write
clean
2D7000
heap default
page read and write
clean
380000
unkown
page read and write
clean
3D3000
unkown
page read and write
clean
564000
heap private
page read and write
clean
326000
unkown
page read and write
clean
3A5000
unkown
page read and write
clean
415000
unkown
page read and write
clean
3AC000
unkown
page read and write
clean
365000
unkown
page read and write
clean
500000
unkown
page read and write
clean
21DB000
heap private
page read and write
clean
327000
heap default
page read and write
clean
38E000
unkown
page read and write
clean
1D10000
unkown image
page readonly
clean
334000
unkown
page read and write
clean
48F0000
unkown image
page readonly
clean
40F000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
5F0000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
3C5000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
1B6000
unkown
page read and write
clean
375000
unkown
page read and write
clean
3FB5000
heap private
page read and write
clean
1D20000
unkown image
page readonly
clean
2200000
unkown
page read and write
clean
570000
heap private
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
33E000
unkown
page read and write
clean
3BF000
unkown
page read and write
clean
3E2F000
unkown
page read and write
clean
710000
unkown image
page readonly
clean
35C000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
315000
unkown
page read and write
clean
320000
heap default
page read and write
clean
2310000
unkown
page read and write
clean
3AA000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
20C5000
heap private
page read and write
clean
49A0000
unkown image
page readonly
clean
2EA000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
324000
unkown
page read and write
clean
20000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
20000
unkown image
page readonly
clean
22AE000
unkown
page read and write
clean
70000
unkown image
page read and write
clean
355000
unkown
page read and write
clean
3A40000
unkown image
page readonly
clean
770000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
4B87000
unkown image
page readonly
clean
20FB000
heap private
page read and write
clean
200000
unkown
page read and write
clean
374000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
2020000
unkown image
page readonly
clean
4A0000
unkown image
page readonly
clean
3B5000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
4B4000
heap private
page read and write
clean
7EFE0000
unkown image
page readonly
clean
1F4000
heap private
page read and write
clean
384000
unkown
page read and write
clean
374000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
315000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
4B47000
unkown image
page readonly
clean
333000
unkown
page read and write
clean
580000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
5E4000
heap private
page read and write
clean
3FF9000
heap private
page read and write
clean
39A0000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
373000
heap default
page read and write
clean
21F5000
heap private
page read and write
clean
There are 197 hidden memdumps, click here to show them.