IOC Report

loading gif

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
malicious
C:\Windows\System32\regsvr32.exe
'C:\Windows\System32\regsvr32.exe' C:\Datop\test.test
malicious
C:\Windows\System32\regsvr32.exe
'C:\Windows\System32\regsvr32.exe' C:\Datop\test1.test
malicious
C:\Windows\System32\regsvr32.exe
'C:\Windows\System32\regsvr32.exe' C:\Datop\test2.test
malicious

URLs

Name
IP
Malicious
https://recapitol.com/pl92fIeHE11X/filht.html
108.179.232.85
malicious
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
unknown
clean
http://www.windows.com/pctv.
unknown
clean
https://iu.ac.bd/QpPq5lm6Xy/fikfh.html
103.28.121.60
clean
http://investor.msn.com
unknown
clean
http://www.msnbc.com/news/ticker.txt
unknown
clean
http://www.icra.org/vocabulary/.
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
http://investor.msn.com/
unknown
clean
http://www.%s.comPA
unknown
clean
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
unknown
clean
http://www.hotmail.com/oe
unknown
clean
https://boogieproductions.com.au/jJNW2LDF/filkfht.html
101.0.113.93
clean
http://servername/isapibackend.dll
unknown
clean
There are 4 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
iu.ac.bd
103.28.121.60
clean
boogieproductions.com.au
101.0.113.93
clean
recapitol.com
108.179.232.85
clean

IPs

IP
Domain
Country
Malicious
101.0.113.93
boogieproductions.com.au
Australia
clean
103.28.121.60
iu.ac.bd
Bangladesh
clean
108.179.232.85
recapitol.com
United States
clean

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
i#'
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel
MTTT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\2F26A
2F26A
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
VBAFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
4''
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\MuiCache\151\52C64B7E
@%SystemRoot%\system32\qagentrt.dll,-10
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\MuiCache\151\52C64B7E
@%SystemRoot%\System32\fveui.dll,-843
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\MuiCache\151\52C64B7E
@%SystemRoot%\System32\fveui.dll,-844
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\MuiCache\151\52C64B7E
@%SystemRoot%\System32\wuaueng.dll,-400
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Place MRU
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 1
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 2
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 3
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 4
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 5
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 6
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 7
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 8
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 9
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 10
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 11
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 12
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 13
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 14
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 15
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 16
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 17
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 18
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 19
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 20
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\3B654
3B654
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Place MRU
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 1
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 2
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 3
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 4
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 5
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 6
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 7
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 8
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 9
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 10
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 11
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 12
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 13
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 14
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 15
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 16
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 17
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 18
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 19
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 20
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\3B8E3
3B8E3
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Security\Trusted Documents
LastPurgeTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
EXCELFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\12891DF7B048CD69D0196C8AD7A754C8A812A08C
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\12891DF7B048CD69D0196C8AD7A754C8A812A08C
Blob
clean
There are 59 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
255000
unkown
page read and write
clean
5FF000
unkown
page read and write
clean
40E000
unkown
page read and write
clean
526000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
136000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
1F4000
heap private
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
256000
unkown
page read and write
clean
496000
unkown
page read and write
clean
2BA000
unkown
page read and write
clean
3A70000
unkown image
page readonly
clean
31F000
unkown
page read and write
clean
454000
heap private
page read and write
clean
235000
unkown
page read and write
clean
4BC7000
unkown image
page readonly
clean
203000
heap default
page read and write
clean
1B7000
heap default
page read and write
clean
680000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
425000
unkown
page read and write
clean
3E95000
heap private
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
1F0000
heap private
page read and write
clean
5F0000
unkown image
page readonly
clean
2B0000
unkown
page read and write
clean
3E99000
heap private
page read and write
clean
2205000
heap private
page read and write
clean
30000
unkown image
page readonly
clean
21A000
unkown
page read and write
clean
42A000
unkown
page read and write
clean
329000
heap default
page read and write
clean
21E0000
heap private
page read and write
clean
2240000
unkown
page read and write
clean
444000
unkown
page read and write
clean
770000
unkown image
page readonly
clean
F0000
unkown
page read and write
clean
F0000
unkown
page read and write
clean
230000
heap default
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
40000
unkown image
page readonly
clean
290000
unkown
page execute and read and write
clean
23A000
unkown
page read and write
clean
ACF000
unkown
page read and write
clean
453000
unkown
page read and write
clean
366000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
20A000
heap default
page read and write
clean
21E5000
heap private
page read and write
clean
29F000
unkown
page read and write
clean
3ED9000
heap private
page read and write
clean
3DE000
heap default
page read and write
clean
445000
unkown
page read and write
clean
2E3000
unkown
page read and write
clean
3ED5000
heap private
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
554000
heap private
page read and write
clean
42C000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
245000
unkown
page read and write
clean
232000
unkown
page read and write
clean
150000
unkown
page read and write
clean
223B000
heap private
page read and write
clean
205B000
heap private
page read and write
clean
674000
heap private
page read and write
clean
1DA0000
unkown image
page readonly
clean
2C5000
unkown
page read and write
clean
495000
unkown
page read and write
clean
29A000
unkown
page read and write
clean
28A000
heap default
page read and write
clean
254000
unkown
page read and write
clean
2D4000
unkown
page read and write
clean
460000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
E0000
unkown image
page read and write
clean
4039000
heap private
page read and write
clean
4F0000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
4CEF000
unkown
page read and write
clean
810000
unkown image
page readonly
clean
1FFE000
unkown
page read and write
clean
245000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
3FA000
heap default
page read and write
clean
6E0000
unkown image
page readonly
clean
1EE000
heap default
page read and write
clean
435000
unkown
page read and write
clean
4035000
heap private
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
2E4000
unkown
page read and write
clean
263000
unkown
page read and write
clean
264000
unkown
page read and write
clean
4D6000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
49E0000
unkown image
page readonly
clean
2BC000
unkown
page read and write
clean
2FD000
heap default
page read and write
clean
E0000
unkown image
page read and write
clean
40000
unkown image
page readonly
clean
1A0000
unkown image
page readonly
clean
237000
heap default
page read and write
clean
2020000
heap private
page read and write
clean
350000
heap private
page read and write
clean
2025000
heap private
page read and write
clean
26E000
heap default
page read and write
clean
435000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
4880000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
3ED0000
heap private
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
234F000
unkown
page read and write
clean
199000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
550000
heap private
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
2B2000
unkown
page read and write
clean
254000
unkown
page read and write
clean
BD000
unkown
page read and write
clean
4840000
unkown image
page readonly
clean
446000
unkown
page read and write
clean
190000
unkown
page execute and read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
3B0000
unkown
page read and write
clean
110000
unkown
page execute and read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
2C0000
heap default
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
440000
heap private
page read and write
clean
7EFE0000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
444000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
2A0000
unkown
page read and write
clean
E0000
unkown image
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
F0000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
179000
unkown
page read and write
clean
2D5000
unkown
page read and write
clean
221B000
heap private
page read and write
clean
6F0000
unkown image
page readonly
clean
100000
unkown
page read and write
clean
2200000
heap private
page read and write
clean
4A27000
unkown image
page readonly
clean
40A000
unkown
page read and write
clean
289000
unkown
page read and write
clean
2D4000
unkown
page read and write
clean
444000
heap private
page read and write
clean
3A80000
unkown image
page readonly
clean
800000
unkown image
page readonly
clean
560000
unkown image
page readonly
clean
3F3000
heap default
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
4030000
heap private
page read and write
clean
4E0000
heap private
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
21E000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
325000
unkown
page read and write
clean
3A7000
heap default
page read and write
clean
283000
heap default
page read and write
clean
2B0000
unkown
page read and write
clean
780000
unkown image
page readonly
clean
4A0000
unkown
page read and write
clean
3A0000
heap default
page read and write
clean
20A0000
unkown image
page readonly
clean
2340000
unkown
page read and write
clean
23C000
unkown
page read and write
clean
454000
unkown
page read and write
clean
320000
unkown
page read and write
clean
2390000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
2D4000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
235000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
2B5000
unkown
page read and write
clean
4CE000
unkown
page read and write
clean
2E6000
unkown
page read and write
clean
2010000
unkown image
page readonly
clean
1B0000
unkown
page read and write
clean
3AC0000
unkown image
page readonly
clean
2C7000
heap default
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
330000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
2D6000
unkown
page read and write
clean
1B0000
heap default
page read and write
clean
4E4000
heap private
page read and write
clean
20A0000
unkown image
page readonly
clean
48F000
unkown
page read and write
clean
2A0000
unkown image
page readonly
clean
422000
unkown
page read and write
clean
186000
unkown
page read and write
clean
1C80000
unkown image
page readonly
clean
2B5000
unkown
page read and write
clean
3E90000
heap private
page read and write
clean
354000
heap private
page read and write
clean
10000
unkown image
page read and write
clean
254000
unkown
page read and write
clean
1D10000
unkown image
page readonly
clean
1A0000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
10000
unkown image
page read and write
clean
444000
unkown
page read and write
clean
425000
unkown
page read and write
clean
2C5000
unkown
page read and write
clean
20000
unkown image
page readonly
clean
C0000
unkown image
page readonly
clean
2A5000
unkown
page read and write
clean
670000
heap private
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
306000
heap default
page read and write
clean
4A67000
unkown image
page readonly
clean
29E000
unkown
page read and write
clean
490000
unkown
page read and write
clean
450000
heap private
page read and write
clean
CAE000
unkown
page read and write
clean
There are 225 hidden memdumps, click here to show them.