IOC Report

loading gif

Files

File Path
Type
Category
Malicious
protocol.xls
Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1251, Name of Creating Application: Microsoft Excel, Create Time/Date: Fri Jun 5 19:19:34 2015, Last Saved Time/Date: Wed Oct 27 10:45:18 2021, Security: 0
initial sample
malicious
C:\Users\user\Desktop\protocol.xls
Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1251, Name of Creating Application: Microsoft Excel, Create Time/Date: Fri Jun 5 19:19:34 2015, Last Saved Time/Date: Wed Oct 27 10:45:18 2021, Security: 0
dropped
malicious
C:\Users\user\AppData\Local\Temp\CD1E.tmp
Composite Document File V2 Document, Cannot read section info
dropped
clean
C:\Users\user\AppData\Local\Temp\~DF2671737F09DCABAC.TMP
data
dropped
clean
C:\Users\user\AppData\Local\Temp\~DF9858F0CABAD63058.TMP
data
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
malicious
C:\Windows\System32\regsvr32.exe
'C:\Windows\System32\regsvr32.exe' C:\Datop\test.test
malicious
C:\Windows\System32\regsvr32.exe
'C:\Windows\System32\regsvr32.exe' C:\Datop\test1.test
malicious
C:\Windows\System32\regsvr32.exe
'C:\Windows\System32\regsvr32.exe' C:\Datop\test2.test
malicious

URLs

Name
IP
Malicious
https://atochagaleria.com.ar/CnijALAyxR/l.html
192.99.46.215
malicious
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
unknown
clean
http://www.windows.com/pctv.
unknown
clean
http://investor.msn.com
unknown
clean
http://www.msnbc.com/news/ticker.txt
unknown
clean
http://www.icra.org/vocabulary/.
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
http://investor.msn.com/
unknown
clean
http://www.%s.comPA
unknown
clean
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
unknown
clean
http://www.hotmail.com/oe
unknown
clean
http://servername/isapibackend.dll
unknown
clean
https://maberic.com/3XRJdBEjFc/l.html
199.79.62.121
clean
https://ost.net.br/toXuNS00/l.html
162.241.2.103
clean
There are 4 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
atochagaleria.com.ar
192.99.46.215
malicious
maberic.com
199.79.62.121
clean
ost.net.br
162.241.2.103
clean

IPs

IP
Domain
Country
Malicious
192.99.46.215
atochagaleria.com.ar
Canada
malicious
162.241.2.103
ost.net.br
United States
clean
199.79.62.121
maberic.com
United States
clean

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
0=#
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel
MTTT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\2D411
2D411
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
VBAFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
)a#
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\MuiCache\151\52C64B7E
@%SystemRoot%\system32\qagentrt.dll,-10
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\MuiCache\151\52C64B7E
@%SystemRoot%\System32\fveui.dll,-843
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\MuiCache\151\52C64B7E
@%SystemRoot%\System32\fveui.dll,-844
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\MuiCache\151\52C64B7E
@%SystemRoot%\System32\wuaueng.dll,-400
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
ProductNonBootFilesIntl_1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Security\Trusted Documents
LastPurgeTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Place MRU
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 1
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 2
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 3
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 4
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 5
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 6
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 7
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 8
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 9
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 10
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 11
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 12
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 13
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 14
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 15
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 16
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 17
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 18
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 19
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 20
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\3D5E5
3D5E5
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Place MRU
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 1
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 2
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 3
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 4
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 5
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 6
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 7
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 8
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 9
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 10
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 11
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 12
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 13
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 14
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 15
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 16
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 17
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 18
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 19
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 20
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\3DDC1
3DDC1
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
EXCELFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\12891DF7B048CD69D0196C8AD7A754C8A812A08C
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\12891DF7B048CD69D0196C8AD7A754C8A812A08C
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
ProductNonBootFilesIntl_1033
clean
There are 61 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
6F0000
heap private
page read and write
clean
30000
unkown image
page readonly
clean
4B6000
unkown
page read and write
clean
2120000
unkown image
page readonly
clean
253000
unkown
page read and write
clean
3A90000
unkown image
page readonly
clean
201B000
heap private
page read and write
clean
3BE000
unkown
page read and write
clean
3EA000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
2165000
heap private
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
43F000
unkown
page read and write
clean
5D0000
unkown image
page readonly
clean
246000
unkown
page read and write
clean
4B17000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
3F5000
unkown
page read and write
clean
1A0000
heap default
page read and write
clean
1FA000
heap default
page read and write
clean
3E5000
unkown
page read and write
clean
70000
unkown image
page read and write
clean
1DE000
heap default
page read and write
clean
406000
unkown
page read and write
clean
235000
unkown
page read and write
clean
1D9000
unkown
page read and write
clean
140000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
3B3000
heap default
page read and write
clean
40000
unkown image
page readonly
clean
560000
unkown
page read and write
clean
22E0000
unkown
page read and write
clean
450000
unkown
page read and write
clean
28F000
unkown
page read and write
clean
2265000
heap private
page read and write
clean
2320000
unkown
page read and write
clean
3DC000
unkown
page read and write
clean
4055000
heap private
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
2060000
unkown image
page readonly
clean
244000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
403000
unkown
page read and write
clean
450000
unkown
page read and write
clean
22C000
unkown
page read and write
clean
E0000
unkown image
page readonly
clean
405000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
80000
unkown
page read and write
clean
3E2000
unkown
page read and write
clean
1E20000
unkown image
page readonly
clean
1FF0000
unkown image
page readonly
clean
1FE0000
heap private
page read and write
clean
100000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
3AA000
heap default
page read and write
clean
3A50000
unkown image
page readonly
clean
295000
unkown
page read and write
clean
1F3000
heap default
page read and write
clean
254000
unkown
page read and write
clean
580000
unkown
page read and write
clean
251F000
stack
page read and write
clean
22A000
unkown
page read and write
clean
286000
unkown
page read and write
clean
20000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
5C0000
heap private
page read and write
clean
245000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
3E5000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
39E000
heap default
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
2C0000
unkown
page read and write
clean
3F89000
heap private
page read and write
clean
3DA000
unkown
page read and write
clean
3F5000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
3B50000
unkown image
page readonly
clean
4A00000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
20A000
unkown
page read and write
clean
23BF000
stack
page read and write
clean
1CF0000
unkown image
page readonly
clean
E0000
unkown image
page read and write
clean
20000
unkown image
page readonly
clean
4079000
heap private
page read and write
clean
3E5000
unkown
page read and write
clean
250000
unkown
page read and write
clean
110000
unkown
page execute and read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
890000
unkown image
page readonly
clean
6F4000
heap private
page read and write
clean
370000
heap private
page read and write
clean
3F80000
heap private
page read and write
clean
109000
unkown
page read and write
clean
244000
unkown
page read and write
clean
3D2000
unkown
page read and write
clean
3CA000
unkown
page read and write
clean
3F5000
unkown
page read and write
clean
3E5000
unkown
page read and write
clean
880000
unkown image
page readonly
clean
440000
unkown
page read and write
clean
219B000
heap private
page read and write
clean
404000
unkown
page read and write
clean
760000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
720000
unkown image
page readonly
clean
380000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
7EFE0000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
225000
unkown
page read and write
clean
3F4000
unkown
page read and write
clean
20000
heap private
page read and write
clean
290000
unkown
page read and write
clean
367000
heap default
page read and write
clean
3F6000
unkown
page read and write
clean
750000
unkown image
page readonly
clean
24000
heap private
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
1CC0000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
445000
unkown
page read and write
clean
4059000
heap private
page read and write
clean
596000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
5A0000
unkown image
page readonly
clean
730000
unkown image
page readonly
clean
4A20000
unkown image
page readonly
clean
486000
unkown
page read and write
clean
38E000
heap default
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
1FE5000
heap private
page read and write
clean
2A0000
unkown image
page readonly
clean
2B4000
heap private
page read and write
clean
480000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
40000
unkown image
page readonly
clean
404000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
460000
unkown
page read and write
clean
413000
unkown
page read and write
clean
3CE000
unkown
page read and write
clean
3BA000
heap default
page read and write
clean
3F85000
heap private
page read and write
clean
F0000
unkown
page read and write
clean
3EC000
unkown
page read and write
clean
130000
unkown image
page readonly
clean
404000
unkown
page read and write
clean
225000
unkown
page read and write
clean
4C07000
unkown image
page readonly
clean
4075000
heap private
page read and write
clean
3D5000
unkown
page read and write
clean
2260000
heap private
page read and write
clean
190000
unkown
page execute and read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
3F4000
unkown
page read and write
clean
120000
unkown image
page readonly
clean
222000
unkown
page read and write
clean
350000
heap default
page read and write
clean
40000
unkown image
page readonly
clean
4BE7000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
3ECF000
stack
page read and write
clean
229B000
heap private
page read and write
clean
1A7000
heap default
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
414000
unkown
page read and write
clean
2B0000
heap private
page read and write
clean
3D5000
unkown
page read and write
clean
496000
unkown
page read and write
clean
3B6000
unkown
page read and write
clean
3BA000
unkown
page read and write
clean
F0000
unkown image
page read and write
clean
700000
unkown image
page readonly
clean
120000
unkown
page execute and read and write
clean
4050000
heap private
page read and write
clean
235000
unkown
page read and write
clean
2160000
heap private
page read and write
clean
244000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
249000
unkown
page read and write
clean
2200000
unkown
page read and write
clean
44F000
unkown
page read and write
clean
20E000
unkown
page read and write
clean
3A3000
heap default
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
404000
unkown
page read and write
clean
3F4000
unkown
page read and write
clean
590000
heap private
page read and write
clean
594000
heap private
page read and write
clean
360000
heap default
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
357000
heap default
page read and write
clean
4070000
heap private
page read and write
clean
4930000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
5C4000
heap private
page read and write
clean
10000
unkown image
page read and write
clean
374000
heap private
page read and write
clean
455000
unkown
page read and write
clean
There are 197 hidden memdumps, click here to show them.