IOC Report

loading gif

Files

File Path
Type
Category
Malicious
subscription-673890410.xlsb
Microsoft Excel 2007+
initial sample
malicious
C:\ProgramData\xkNURUQaCiKQrGY.rtf
HTML document, ASCII text, with very long lines, with CRLF line terminators
dropped
malicious
C:\Users\user\Desktop\~$subscription-673890410.xlsb
data
dropped
malicious
C:\ProgramData\dDVVHyrpueA.txt
ASCII text, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\Q2W5VWUFL5VCMQ7JQPETG3CCTYX72Z4R25PDG[1].txt
ASCII text, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\6F135607.png
PNG image data, 295 x 52, 8-bit/color RGB, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\BEF1285C.png
PNG image data, 238 x 337, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Temp\5042.tmp
Microsoft Excel 2007+
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
"C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /automation -Embedding
malicious
C:\Windows\System32\wbem\WMIC.exe
wmic process call create "mshta C:\ProgramData\xkNURUQaCiKQrGY.rtf"
malicious
C:\Windows\System32\mshta.exe
mshta C:\ProgramData\xkNURUQaCiKQrGY.rtf
clean

URLs

Name
IP
Malicious
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
unknown
clean
http://www.windows.com/pctv.
unknown
clean
http://investor.msn.com
unknown
clean
http://www.msnbc.com/news/ticker.txt
unknown
clean
http://www.%s.comPA
unknown
clean
http://www.icra.org/vocabulary/.
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
http://132.148.135.183:8080/Q2W5VWUFL5VCMQ7JQPETG3CCTYX72Z4R25PDG
132.148.135.183
clean
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
unknown
clean
http://www.hotmail.com/oe
unknown
clean
http://servername/isapibackend.dll
unknown
clean
http://investor.msn.com/
unknown
clean
There are 2 hidden URLs, click here to show them.

IPs

IP
Domain
Country
Malicious
132.148.135.183
unknown
United States
clean

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
?c$
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel
MTTT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\2EB0A
2EB0A
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
VBAFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
%l$
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
ProductNonBootFilesIntl_1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
OriginalAttachmentPath
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
TemporaryAttachmentName
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109A10090400100000000F01FEC\Usage
OutlookMAPI2Intl_1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Security\Trusted Documents
LastPurgeTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
EXCELFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
ProductNonBootFilesIntl_1033
clean
There are 7 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
7FFFFFC2000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
278000
unkown
page read and write
clean
5C8000
heap default
page read and write
clean
175000
unkown
page read and write
clean
595000
heap default
page read and write
clean
10000
unkown image
page read and write
clean
2730000
heap private
page read and write
clean
29D000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
22E5000
heap private
page read and write
clean
AD000
unkown
page read and write
clean
19D000
heap default
page read and write
clean
2DD5000
unkown
page read and write
clean
39EF000
stack
page read and write
clean
20000
unkown image
page read and write
clean
18D000
unkown
page read and write
clean
2BE0000
heap private
page read and write
clean
2B00000
unkown
page read and write
clean
57F000
stack
page read and write
clean
4F7F000
unkown
page read and write
clean
2CC5000
heap private
page read and write
clean
14A000
unkown
page read and write
clean
29F000
unkown
page read and write
clean
193000
unkown
page read and write
clean
54D0000
heap private
page read and write
clean
3180000
heap private
page read and write
clean
4F6F000
unkown
page read and write
clean
2B2C000
unkown
page read and write
clean
2B30000
unkown
page read and write
clean
346000
unkown
page read and write
clean
2CC0000
heap private
page read and write
clean
3F4000
heap private
page read and write
clean
4F56000
unkown
page read and write
clean
120000
unkown
page read and write
clean
26A000
unkown
page read and write
clean
2630000
unkown image
page readonly
clean
29D000
unkown
page read and write
clean
29F000
unkown
page read and write
clean
2B14000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
170000
unkown
page read and write
clean
4F4000
heap private
page read and write
clean
2B10000
unkown
page read and write
clean
26B000
unkown
page read and write
clean
29F000
unkown
page read and write
clean
2D70000
heap private
page read and write
clean
3580000
heap private
page read and write
clean
2326000
heap private
page read and write
clean
1D0000
unkown image
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
2B18000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
2B7C000
unkown
page read and write
clean
2B39000
unkown
page read and write
clean
29A000
unkown
page read and write
clean
3110000
unkown
page read and write
clean
2D50000
heap private
page read and write
clean
7EFE0000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
25B000
unkown
page read and write
clean
1670000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
2B60000
unkown
page read and write
clean
160000
unkown image
page read and write
clean
1C20000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
2BE4000
heap private
page read and write
clean
1B2000
unkown
page read and write
clean
2B24000
unkown
page read and write
clean
500000
unkown image
page readonly
clean
40000
unkown image
page readonly
clean
2B08000
unkown
page read and write
clean
54F000
heap default
page read and write
clean
2AE8000
unkown
page read and write
clean
2B88000
unkown
page read and write
clean
690000
unkown image
page readonly
clean
2DD1000
unkown
page read and write
clean
1C9000
unkown
page read and write
clean
345E000
stack
page read and write
clean
2BA0000
unkown
page read and write
clean
378D000
stack
page read and write
clean
5FF000
stack
page read and write
clean
2B28000
unkown
page read and write
clean
4F7000
heap default
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
182000
unkown
page read and write
clean
543E000
stack
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
50C0000
heap private
page read and write
clean
4F54000
unkown
page read and write
clean
160000
heap default
page read and write
clean
2DD8000
unkown
page read and write
clean
1F40000
heap private
page read and write
clean
56B000
heap default
page read and write
clean
2CFB000
heap private
page read and write
clean
219F000
stack
page read and write
clean
52C0000
heap private
page read and write
clean
22E0000
heap private
page read and write
clean
4F58000
unkown
page read and write
clean
29A000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
4F4E000
unkown
page read and write
clean
4F60000
unkown
page read and write
clean
2DD4000
unkown
page read and write
clean
2A70000
unkown image
page readonly
clean
172000
unkown
page read and write
clean
1FC0000
heap private
page read and write
clean
278000
unkown
page read and write
clean
450000
heap private
page read and write
clean
4F96000
unkown
page read and write
clean
1C9000
unkown
page read and write
clean
2DDB000
unkown
page read and write
clean
4F49000
unkown
page read and write
clean
17D000
unkown
page read and write
clean
2B4000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
1AE000
unkown
page read and write
clean
217000
heap default
page read and write
clean
586000
heap default
page read and write
clean
296000
unkown
page read and write
clean
200000
heap private
page read and write
clean
2DD9000
unkown
page read and write
clean
2AFC000
unkown
page read and write
clean
2B20000
unkown
page read and write
clean
278000
unkown
page read and write
clean
2DD2000
unkown
page read and write
clean
2DD0000
unkown
page read and write
clean
2DDA000
unkown
page read and write
clean
2A80000
unkown image
page read and write
clean
1350000
unkown image
page readonly
clean
2C7000
unkown
page read and write
clean
355F000
stack
page read and write
clean
2C70000
unkown image
page readonly
clean
1AC000
unkown
page read and write
clean
232F000
heap private
page read and write
clean
1C9000
unkown
page read and write
clean
4F66000
unkown
page read and write
clean
169000
unkown
page read and write
clean
2050000
heap private
page read and write
clean
2B94000
unkown
page read and write
clean
6B72000
unkown image
page read and write
clean
2950000
heap private
page read and write
clean
2B80000
unkown
page read and write
clean
C0000
unkown image
page readonly
clean
1AB000
heap default
page read and write
clean
3F0000
heap private
page read and write
clean
2DDC000
unkown
page read and write
clean
4F40000
unkown
page read and write
clean
260000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
5750000
unkown
page read and write
clean
186000
unkown
page read and write
clean
268000
unkown
page read and write
clean
2B68000
unkown
page read and write
clean
4F68000
unkown
page read and write
clean
4EC0000
heap private
page read and write
clean
4F6B000
unkown
page read and write
clean
2B6C000
unkown
page read and write
clean
2A7E000
stack
page read and write
clean
2AA0000
unkown
page read and write
clean
3EE7000
unkown image
page readonly
clean
3CFF000
stack
page read and write
clean
316000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
3300000
unkown
page read and write
clean
205000
heap private
page read and write
clean
1C9000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
2DAB000
heap private
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
269000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
2C2E000
stack
page read and write
clean
40000
unkown image
page readonly
clean
2AF8000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
2DD3000
unkown
page read and write
clean
4F0000
heap private
page read and write
clean
10000
unkown image
page read and write
clean
5B7000
heap default
page read and write
clean
30E0000
unkown image
page readonly
clean
1AE000
unkown
page read and write
clean
56D0000
heap private
page read and write
clean
4EC5000
heap private
page read and write
clean
4F86000
unkown
page read and write
clean
3300000
unkown
page read and write
clean
32FF000
stack
page read and write
clean
7EFE0000
unkown image
page readonly
clean
B0000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
114000
heap private
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
52E000
heap default
page read and write
clean
2DD7000
unkown
page read and write
clean
29A000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
285E000
stack
page read and write
clean
3185000
heap private
page read and write
clean
2B3000
unkown
page read and write
clean
2C4000
unkown
page read and write
clean
234B000
heap private
page read and write
clean
2B0C000
unkown
page read and write
clean
2B50000
unkown
page read and write
clean
2B58000
unkown
page read and write
clean
278000
unkown
page read and write
clean
2BA4000
unkown
page read and write
clean
2DD6000
unkown
page read and write
clean
2340000
heap private
page read and write
clean
4F79000
unkown
page read and write
clean
6F62000
unkown image
page readonly
clean
3B3F000
stack
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
3D00000
unkown image
page readonly
clean
2B34000
unkown
page read and write
clean
40E0000
unkown image
page readonly
clean
1A6000
heap default
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
110000
heap private
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
1AE000
unkown
page read and write
clean
2D75000
heap private
page read and write
clean
11A000
heap private
page read and write
clean
B5F000
stack
page read and write
clean
3336000
unkown
page read and write
clean
310000
unkown
page read and write
clean
14D0000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
1C6000
unkown
page read and write
clean
2AEC000
unkown
page read and write
clean
2B49000
unkown
page read and write
clean
4F72000
unkown
page read and write
clean
30D0000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
1D0000
unkown
page read and write
clean
150000
unkown image
page readonly
clean
5040000
heap private
page read and write
clean
4F52000
unkown
page read and write
clean
231B000
heap private
page read and write
clean
14E0000
unkown image
page readonly
clean
156000
unkown
page read and write
clean
680000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
1B0000
unkown
page read and write
clean
260000
unkown
page read and write
clean
2B10000
heap private
page read and write
clean
5DD000
heap default
page read and write
clean
2B90000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
210000
heap default
page read and write
clean
3189000
heap private
page read and write
clean
24E000
heap default
page read and write
clean
167000
heap default
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
18F000
unkown
page read and write
clean
29D000
unkown
page read and write
clean
2AF0000
unkown
page read and write
clean
2B5C000
unkown
page read and write
clean
56AF000
stack
page read and write
clean
2B84000
unkown
page read and write
clean
11D000
heap private
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
2B04000
unkown
page read and write
clean
4F0000
heap default
page read and write
clean
4F6D000
unkown
page read and write
clean
2344000
heap private
page read and write
clean
There are 259 hidden memdumps, click here to show them.