IOC Report

loading gif

Files

File Path
Type
Category
Malicious
inquiry[2021.09.23_12-51].xlsb
Zip archive data, at least v2.0 to extract
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\a435gfhs109[1].cms
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
downloaded
malicious
C:\Users\Public\codec.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\CE192CE4.png
PNG image data, 1179 x 832, 8-bit/color RGB, non-interlaced
dropped
clean
C:\Users\user\Desktop\~$inquiry[2021.09.23_12-51].xlsb
data
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
malicious
C:\Windows\System32\wbem\WMIC.exe
wmic.exe process call create 'regsvr32 -s C:\Users\Public\codec.dll'
malicious
C:\Windows\System32\regsvr32.exe
regsvr32 -s C:\Users\Public\codec.dll
malicious
C:\Windows\SysWOW64\regsvr32.exe
-s C:\Users\Public\codec.dll
malicious

URLs

Name
IP
Malicious
https://iqwasithealth.com/wp-content/uploads/2019/06/a435gfhs109.cms
50.87.248.41
malicious
http://www.%s.comPA
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
http://apt.updateffboruse.com/_2BYjuB36DkhB1eXLxT/icgzR9URog3BC5Xw8V6nIs/1N91Pgd5TeSwG/3boxgKnH/mcET
unknown
clean
http://servername/isapibackend.dll
unknown
clean

Domains

Name
IP
Malicious
iqwasithealth.com
50.87.248.41
malicious
app.updatebrouser.com
unknown
malicious
apt.updateffboruse.com
unknown
malicious

IPs

IP
Domain
Country
Malicious
50.87.248.41
iqwasithealth.com
United States
malicious

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
|#(
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel
MTTT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\2DEBB
2DEBB
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
VBAFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
4'(
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\MuiCache\151\52C64B7E
@%SystemRoot%\system32\qagentrt.dll,-10
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\MuiCache\151\52C64B7E
@%SystemRoot%\System32\fveui.dll,-843
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\MuiCache\151\52C64B7E
@%SystemRoot%\System32\fveui.dll,-844
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\MuiCache\151\52C64B7E
@%SystemRoot%\System32\wuaueng.dll,-400
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\3311E
3311E
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
ProductNonBootFilesIntl_1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Security\Trusted Documents
LastPurgeTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
EXCELFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\12891DF7B048CD69D0196C8AD7A754C8A812A08C
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\12891DF7B048CD69D0196C8AD7A754C8A812A08C
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
ProductNonBootFilesIntl_1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
ProductNonBootFilesIntl_1033
clean
There are 17 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
1C0000
unkown
page execute and read and write
malicious
32F8000
heap private
page read and write
malicious
2A59000
heap private
page read and write
malicious
7EFDF000
unkown
page read and write
clean
26E0000
heap private
page read and write
clean
3512000
heap private
page read and write
clean
170000
unkown
page read and write
clean
3A6000
unkown
page read and write
clean
180000
unkown
page read and write
clean
3CD000
unkown
page read and write
clean
180000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
2EB000
unkown
page read and write
clean
34F4000
heap private
page read and write
clean
50000
unkown image
page readonly
clean
7EFC2000
unkown image
page readonly
clean
3595000
unkown
page read and write
clean
397000
unkown
page read and write
clean
3F7000
unkown
page read and write
clean
180000
unkown
page read and write
clean
7EFB0000
unkown image
page readonly
clean
4C4000
heap default
page read and write
clean
2BC0000
unkown
page read and write
clean
2BC8000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
290000
heap private
page read and write
clean
180000
unkown
page read and write
clean
216000
heap private
page read and write
clean
3DC000
stack
page read and write
clean
7EFD0000
unkown image
page readonly
clean
2F2000
unkown
page read and write
clean
30000
unkown image
page read and write
clean
2BC7000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
1CC0000
unkown image
page readonly
clean
3090000
heap private
page read and write
clean
7EFB2000
unkown image
page readonly
clean
1A9000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
518000
heap default
page read and write
clean
7EFC2000
unkown image
page readonly
clean
3FF000
unkown
page read and write
clean
120000
unkown
page execute and read and write
clean
210000
heap private
page read and write
clean
4A6000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
23A0000
heap private
page read and write
clean
2E98000
heap private
page read and write
clean
5A0000
unkown image
page readonly
clean
37E000
heap default
page read and write
clean
2E7E000
stack
page read and write
clean
40000
unkown image
page readonly
clean
180000
unkown
page read and write
clean
21A4000
heap private
page read and write
clean
39A000
unkown
page read and write
clean
30C000
stack
page read and write
clean
224B000
heap private
page read and write
clean
2E90000
heap private
page read and write
clean
2020000
heap private
page read and write
clean
24BF000
stack
page read and write
clean
1FDD000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
16A000
unkown
page read and write
clean
262E000
stack
page read and write
clean
20000
unkown image
page readonly
clean
6E2AE000
unkown image
page execute read
clean
3590000
unkown
page read and write
clean
4A0000
heap default
page read and write
clean
7EFB0000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
277000
heap default
page read and write
clean
1D90000
unkown image
page readonly
clean
2530000
heap private
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
1C0000
heap private
page read and write
clean
2F00000
heap private
page read and write
clean
4DF000
heap default
page read and write
clean
21C2000
heap private
page read and write
clean
280000
unkown
page read and write
clean
D0000
unkown image
page readonly
clean
20D000
stack
page read and write
clean
2210000
heap private
page read and write
clean
3CA000
unkown
page read and write
clean
2F3000
unkown
page read and write
clean
180000
unkown
page read and write
clean
6E2A5000
unkown image
page read and write
clean
2F8000
unkown
page read and write
clean
440000
unkown image
page readonly
clean
266C000
stack
page read and write
clean
7EFE0000
unkown image
page readonly
clean
E0000
unkown image
page read and write
clean
50C000
heap default
page read and write
clean
3A8000
unkown
page read and write
clean
3A8000
unkown
page read and write
clean
2E4000
heap private
page read and write
clean
2F4000
unkown
page read and write
clean
170000
unkown image
page readonly
clean
26AD000
stack
page read and write
clean
180000
unkown
page read and write
clean
6E2CE000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
6E2A3000
unkown image
page readonly
clean
3CA000
unkown
page read and write
clean
7EFB2000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
6E30E000
unkown image
page readonly
clean
4A7000
heap default
page read and write
clean
2BC9000
unkown
page read and write
clean
25F0000
heap private
page read and write
clean
280000
unkown
page read and write
clean
E0000
unkown image
page read and write
clean
270000
unkown
page read and write
clean
100000
unkown
page read and write
clean
2EB6000
heap private
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
1AA000
unkown image
page read and write
clean
370000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
310000
heap default
page read and write
clean
3095000
heap private
page read and write
clean
322F000
stack
page read and write
clean
18B000
unkown
page read and write
clean
3524000
heap private
page read and write
clean
570000
unkown image
page readonly
clean
340000
heap default
page read and write
clean
1A1000
unkown image
page execute read
clean
20C0000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
200F000
stack
page read and write
clean
6E2A0000
unkown image
page readonly
clean
2AD8000
heap private
page read and write
clean
60000
unkown image
page readonly
clean
45E000
stack
page read and write
clean
3A8000
unkown
page read and write
clean
5D0000
unkown image
page readonly
clean
39B000
unkown
page read and write
clean
2F5000
unkown
page read and write
clean
20000
unkown image
page read and write
clean
37B0000
heap private
page read and write
clean
25D000
unkown
page read and write
clean
270000
heap default
page read and write
clean
1A0000
unkown image
page readonly
clean
800000
unkown image
page readonly
clean
6E2A1000
unkown image
page execute read
clean
180000
unkown
page read and write
clean
21E0000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
730000
unkown image
page readonly
clean
990000
unkown image
page readonly
clean
670000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
3CA000
unkown
page read and write
clean
2BCA000
unkown
page read and write
clean
20000
unkown image
page readonly
clean
2215000
heap private
page read and write
clean
3F3000
unkown
page read and write
clean
34CE000
stack
page read and write
clean
40000
unkown image
page readonly
clean
2840000
unkown image
page readonly
clean
2DEF000
stack
page read and write
clean
10000
unkown image
page read and write
clean
30000
unkown image
page readonly
clean
347000
heap default
page read and write
clean
38B000
unkown
page read and write
clean
180000
unkown
page read and write
clean
2D0000
unkown image
page read and write
clean
2BC2000
unkown
page read and write
clean
208B000
heap private
page read and write
clean
390000
unkown
page read and write
clean
5C0000
unkown image
page readonly
clean
2BCC000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
2BC1000
unkown
page read and write
clean
3A8000
unkown
page read and write
clean
660000
heap private
page read and write
clean
2CA000
heap default
page read and write
clean
1A6000
unkown
page read and write
clean
7EFD0000
unkown image
page readonly
clean
3CD000
unkown
page read and write
clean
F0000
unkown
page read and write
clean
3E2000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
720000
unkown image
page readonly
clean
4D9000
heap default
page read and write
clean
3CA000
unkown
page read and write
clean
2BC5000
unkown
page read and write
clean
2C3000
heap default
page read and write
clean
1FC0000
unkown
page read and write
clean
2025000
heap private
page read and write
clean
1C4000
heap private
page read and write
clean
21A0000
heap private
page read and write
clean
205B000
heap private
page read and write
clean
2BC4000
unkown
page read and write
clean
2E8000
heap default
page read and write
clean
2E0000
heap private
page read and write
clean
3F6000
unkown
page read and write
clean
7F0000
unkown image
page readonly
clean
180000
unkown
page read and write
clean
3476000
unkown
page read and write
clean
8C0000
unkown image
page readonly
clean
470000
unkown
page read and write
clean
2920000
heap private
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
16A000
unkown
page read and write
clean
6E2A6000
unkown image
page readonly
clean
34F0000
heap private
page read and write
clean
2080000
heap private
page read and write
clean
3440000
unkown
page read and write
clean
2066000
heap private
page read and write
clean
2084000
heap private
page read and write
clean
33DD000
stack
page read and write
clean
1B0000
heap private
page read and write
clean
27C0000
heap private
page read and write
clean
1B60000
unkown image
page readonly
clean
29E0000
heap private
page read and write
clean
3E4000
unkown
page read and write
clean
1AC000
unkown image
page readonly
clean
6E2F6000
unkown image
page read and write
clean
2BCB000
unkown
page read and write
clean
6E2F8000
unkown image
page execute and read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
2B40000
heap private
page read and write
clean
6E2A0000
unkown image
page readonly
clean
206F000
heap private
page read and write
clean
2AE000
heap default
page read and write
clean
30CB000
heap private
page read and write
clean
7EFC0000
unkown image
page readonly
clean
664000
heap private
page read and write
clean
7EFC0000
unkown image
page readonly
clean
399000
unkown
page read and write
clean
2BC6000
unkown
page read and write
clean
3CD000
unkown
page read and write
clean
2E4000
unkown
page read and write
clean
336E000
stack
page read and write
clean
180000
unkown
page read and write
clean
1A0000
unkown image
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
2BC3000
unkown
page read and write
clean
180000
unkown
page execute and read and write
clean
399000
unkown
page read and write
clean
398000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
1EE0000
heap private
page read and write
clean
2E3C000
stack
page read and write
clean
180000
unkown
page read and write
clean
There are 240 hidden memdumps, click here to show them.