IOC Report

loading gif

Files

File Path
Type
Category
Malicious
Fra FAC-ES101-2107-03806.doc.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
data
dropped
clean
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Microsoft Cabinet archive data, 61157 bytes, 1 file
dropped
clean
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
data
dropped
clean
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
data
modified
clean
\Device\ConDrv
ASCII text, with CRLF line terminators
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\Fra FAC-ES101-2107-03806.doc.exe
'C:\Users\user\Desktop\Fra FAC-ES101-2107-03806.doc.exe'
malicious
C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe
'C:\Users\user\Desktop\Fra FAC-ES101-2107-03806.doc.exe'
malicious
C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe
'C:\Users\user\Desktop\Fra FAC-ES101-2107-03806.doc.exe'
malicious
C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe
'C:\Users\user\Desktop\Fra FAC-ES101-2107-03806.doc.exe'
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
clean

URLs

Name
IP
Malicious
http://mail.tccinfaes.com
unknown
malicious
http://127.0.0.1:HTTP/1.1
unknown
clean
http://x1.i.lencr.org/
unknown
clean
http://DynDns.comDynDNS
unknown
clean
http://L3TFBaO3nLwUP4KRw.comt-
unknown
clean
https://doc-04-ak-docs.googleusercontent.com/q
unknown
clean
http://cps.letsencrypt.org0
unknown
clean
https://doc-04-ak-docs.googleusercontent.com/
unknown
clean
https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip%tordir%%ha
unknown
clean
https://doc-04-ak-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/qc1fdhq835moktnu71nht8627dleqonv/1634123175000/00240525256395999725/*/1sPphH_DrSUT3UeS4UDzeclKCi9pqFiSe?e=download
142.250.185.161
clean
https://drive.google.com/
unknown
clean
http://x1.c.lencr.org/0
unknown
clean
http://x1.i.lencr.org/0
unknown
clean
http://tccinfaes.com
unknown
clean
http://aSuCYu.com
unknown
clean
http://r3.o.lencr.org0
unknown
clean
https://support.google.com/chrome/?p=plugin_flash
unknown
clean
https://doc-04-ak-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/qc1fdhq8
unknown
clean
https://drive.google.com/(&
unknown
clean
http://r3.i.lencr.org/0)
unknown
clean
http://L3TFBaO3nLwUP4KRw.com
unknown
clean
There are 11 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
tccinfaes.com
188.93.227.195
malicious
mail.tccinfaes.com
unknown
malicious
drive.google.com
142.250.185.174
clean
googlehosted.l.googleusercontent.com
142.250.185.161
clean
doc-04-ak-docs.googleusercontent.com
unknown
clean
x1.i.lencr.org
unknown
clean

IPs

IP
Domain
Country
Malicious
188.93.227.195
tccinfaes.com
Portugal
malicious
142.250.185.174
drive.google.com
United States
clean
142.250.185.161
googlehosted.l.googleusercontent.com
United States
clean

Memdumps

Base Address
Regiontype
Protect
Malicious
1DD61000
unkown
page read and write
malicious
2AB0000
unkown
page execute and read and write
malicious
1DE814A8000
unkown
page read and write
clean
CF1000
unkown
page read and write
clean
2A070FD4000
heap default
page read and write
clean
1360000
stack
page read and write
clean
20844710000
unkown
page read and write
clean
1DE64000
unkown
page read and write
clean
1FD68000
unkown
page read and write
clean
7FF517DD2000
unkown image
page readonly
clean
F51000
unkown
page read and write
clean
C70000
unkown
page read and write
clean
7FF4FF176000
unkown image
page readonly
clean
2A071A5C000
unkown
page read and write
clean
208404C3000
unkown
page read and write
clean
2083E680000
unkown image
page readonly
clean
7FF547ACB000
unkown image
page readonly
clean
7FF517D46000
unkown image
page readonly
clean
F51000
unkown
page read and write
clean
7FF5A2200000
unkown image
page readonly
clean
7DF557DB0000
unkown image
page readonly
clean
F51000
unkown
page read and write
clean
1DD15000
unkown
page read and write
clean
1360000
stack
page read and write
clean
7DF581890000
unkown image
page readonly
clean
F51000
unkown
page read and write
clean
1DE81486000
unkown
page read and write
clean
1360000
stack
page read and write
clean