IOC Report

loading gif

Files

File Path
Type
Category
Malicious
payment 435975469.xlsb
Microsoft Excel 2007+
initial sample
malicious
C:\ProgramData\EYCmMYHJOyR.rtf
HTML document, ASCII text, with very long lines, with CRLF line terminators
dropped
malicious
C:\Users\user\Desktop\~$payment 435975469.xlsb
data
dropped
malicious
C:\ProgramData\hgcwdJhz.txt
ASCII text, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\Q2W5VWUFL5VCMQ7JQPETG3CCTYX72Z4R25PDG[1].txt
ASCII text, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\70DEA7D3.png
PNG image data, 286 x 48, 8-bit/color RGB, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\D5C797B8.png
PNG image data, 237 x 336, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Temp\57FF.tmp
Microsoft Excel 2007+
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
"C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /automation -Embedding
malicious
C:\Windows\System32\wbem\WMIC.exe
wmic process call create "mshta C:\ProgramData\EYCmMYHJOyR.rtf"
malicious
C:\Windows\System32\mshta.exe
mshta C:\ProgramData\EYCmMYHJOyR.rtf
clean

URLs

Name
IP
Malicious
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
unknown
clean
http://www.windows.com/pctv.
unknown
clean
http://investor.msn.com
unknown
clean
http://www.msnbc.com/news/ticker.txt
unknown
clean
http://www.%s.comPA
unknown
clean
http://www.icra.org/vocabulary/.
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
unknown
clean
http://www.hotmail.com/oe
unknown
clean
http://servername/isapibackend.dll
unknown
clean
http://investor.msn.com/
unknown
clean
http://139.59.64.195:8080/Q2W5VWUFL5VCMQ7JQPETG3CCTYX72Z4R25PDG
139.59.64.195
clean
There are 2 hidden URLs, click here to show them.

IPs

IP
Domain
Country
Malicious
139.59.64.195
unknown
Singapore
clean

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
jr.
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel
MTTT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\2F509
2F509
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
VBAFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
6z.
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
ProductNonBootFilesIntl_1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
OriginalAttachmentPath
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
TemporaryAttachmentName
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109A10090400100000000F01FEC\Usage
OutlookMAPI2Intl_1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Security\Trusted Documents
LastPurgeTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
EXCELFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
ProductNonBootFilesIntl_1033
clean
There are 7 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
23B0000
unkown
page read and write
clean
50D000
heap private
page read and write
clean
40000
unkown image
page readonly
clean
507F000
stack
page read and write
clean
37B000
heap default
page read and write
clean
2334000
unkown
page read and write
clean
2B02000
unkown
page read and write
clean
2B06000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
4875000
heap private
page read and write
clean
23B8000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
2380000
unkown
page read and write
clean
170000
heap private
page read and write
clean
303E000
stack
page read and write
clean
2310000
heap private
page read and write
clean
4915000
unkown
page read and write
clean
34B0000
heap private
page read and write
clean
10000
unkown image
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
470000
unkown image
page readonly
clean
E0000
heap default
page read and write
clean
3360000
unkown image
page readonly
clean
2F2D000
stack
page read and write
clean
3B5000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
C00000
unkown image
page readonly
clean
2D70000
heap private
page read and write
clean
2379000
unkown
page read and write
clean
174000
heap private
page read and write
clean
23AC000
unkown
page read and write
clean
380000
unkown
page read and write
clean
2B0B000
unkown
page read and write
clean
2B07000
unkown
page read and write
clean
2348000
unkown
page read and write
clean
2810000
heap private
page read and write
clean
4907000
unkown
page read and write
clean
2B03000
unkown
page read and write
clean
2D8000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
2FF000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
2358000
unkown
page read and write
clean
239C000
unkown
page read and write
clean
2398000
unkown
page read and write
clean
D0000
unkown
page read and write
clean
2364000
unkown
page read and write
clean
232C000
unkown
page read and write
clean
2FF000
unkown
page read and write
clean
20BF000
stack
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
210000
unkown image
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
20000
unkown image
page read and write
clean
324E000
stack
page read and write
clean
370000
unkown
page read and write
clean
39C000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
584000
heap private
page read and write
clean
E7000
heap default
page read and write
clean
314000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
4921000
unkown
page read and write
clean
2A3B000
heap private
page read and write
clean
37C000
unkown
page read and write
clean
6492000
unkown image
page readonly
clean
2369000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
2FF000
unkown
page read and write
clean
398000
unkown
page read and write
clean
25CE000
stack
page read and write
clean
2A5E000
stack
page read and write
clean
2B04000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
2328000
unkown
page read and write
clean
49F0000
heap private
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
3B7000
unkown
page read and write
clean
3060000
unkown
page read and write
clean
1E0000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
1C9000
heap default
page read and write
clean
22F6000
heap private
page read and write
clean
40000
unkown image
page readonly
clean
2290000
heap private
page read and write
clean
4917000
unkown
page read and write
clean
2344000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
1ED0000
heap private
page read and write
clean
500000
heap private
page read and write
clean
4913000
unkown
page read and write
clean
2C0000
unkown
page read and write
clean
150000
unkown image
page readonly
clean
74F000
stack
page read and write
clean
DA0000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
324000
unkown
page read and write
clean
25D0000
heap private
page read and write
clean
2AE000
heap default
page read and write
clean
28F0000
heap private
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
25D000
unkown
page read and write
clean
21A0000
unkown image
page readonly
clean
21D0000
unkown
page read and write
clean
2A00000
heap private
page read and write
clean
2B09000
unkown
page read and write
clean
3CD0000
heap private
page read and write
clean
504000
heap private
page read and write
clean
5F0000
unkown image
page readonly
clean
1B90000
unkown image
page readonly
clean
4B50000
unkown
page read and write
clean
1A4000
heap default
page read and write
clean
2314000
heap private
page read and write
clean
2B00000
unkown
page read and write
clean
21B0000
unkown image
page read and write
clean
235C000
unkown
page read and write
clean
2B08000
unkown
page read and write
clean
362000
unkown
page read and write
clean
327000
unkown
page read and write
clean
492E000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
2340000
unkown
page read and write
clean
60A2000
unkown image
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
14A000
unkown
page read and write
clean
2CB000
unkown
page read and write
clean
2B05000
unkown
page read and write
clean
260B000
heap private
page read and write
clean
277000
heap default
page read and write
clean
180000
unkown
page read and write
clean
2350000
unkown
page read and write
clean
3040000
unkown
page read and write
clean
2390000
unkown
page read and write
clean
372000
unkown
page read and write
clean
337000
heap default
page read and write
clean
4AD0000
heap private
page read and write
clean
36D000
heap default
page read and write
clean
30000
unkown image
page readonly
clean
22FF000
heap private
page read and write
clean
580000
heap private
page read and write
clean
23C0000
unkown
page read and write
clean
238C000
unkown
page read and write
clean
310000
unkown
page read and write
clean
50A000
heap private
page read and write
clean
106000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
2320000
unkown
page read and write
clean
4903000
unkown
page read and write
clean
346000
unkown
page read and write
clean
493F000
unkown
page read and write
clean
2260000
unkown image
page readonly
clean
2318000
unkown
page read and write
clean
3B2000
unkown
page read and write
clean
22B5000
heap private
page read and write
clean
3CD5000
heap private
page read and write
clean
376000
heap default
page read and write
clean
270000
heap default
page read and write
clean
322F000
stack
page read and write
clean
26A0000
heap private
page read and write
clean
23D0000
unkown
page read and write
clean
2360000
unkown
page read and write
clean
305F000
stack
page read and write
clean
2CA000
unkown
page read and write
clean
2FA000
unkown
page read and write
clean
34B5000
heap private
page read and write
clean
2BAE000
stack
page read and write
clean
2B0C000
unkown
page read and write
clean
181000
heap default
page read and write
clean
600000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
22B0000
heap private
page read and write
clean
490E000
unkown
page read and write
clean
C10000
unkown image
page readonly
clean
312000
unkown
page read and write
clean
2410000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
2FF000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
2C8000
unkown
page read and write
clean
3BF0000
heap private
page read and write
clean
4910000
unkown
page read and write
clean
24F0000
unkown
page read and write
clean
2F00000
unkown image
page readonly
clean
3740000
unkown image
page readonly
clean
48F0000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
60E000
stack
page read and write
clean
23C4000
unkown
page read and write
clean
231C000
unkown
page read and write
clean
25D5000
heap private
page read and write
clean
2294000
heap private
page read and write
clean
379000
unkown
page read and write
clean
23B4000
unkown
page read and write
clean
2D8000
unkown
page read and write
clean
2FF000
unkown
page read and write
clean
3B2000
unkown
page read and write
clean
29EE000
stack
page read and write
clean
160000
unkown image
page read and write
clean
47F0000
heap private
page read and write
clean
23D4000
unkown
page read and write
clean
53F000
stack
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
22EB000
heap private
page read and write
clean
2170000
heap private
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
231B000
heap private
page read and write
clean
233C000
unkown
page read and write
clean
491A000
unkown
page read and write
clean
3547000
unkown image
page readonly
clean
2250000
unkown image
page readonly
clean
4905000
unkown
page read and write
clean
2770000
heap private
page read and write
clean
11E000
heap default
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
2FA000
unkown
page read and write
clean
2B0A000
unkown
page read and write
clean
359000
unkown
page read and write
clean
2A05000
heap private
page read and write
clean
2FA000
unkown
page read and write
clean
306000
unkown
page read and write
clean
4870000
heap private
page read and write
clean
2B01000
unkown
page read and write
clean
2FF000
unkown
page read and write
clean
2D3F000
stack
page read and write
clean
3096000
unkown
page read and write
clean
2354000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
4700000
heap private
page read and write
clean
48F7000
unkown
page read and write
clean
2D8000
unkown
page read and write
clean
2338000
unkown
page read and write
clean
3A6000
unkown
page read and write
clean
3CD9000
heap private
page read and write
clean
4927000
unkown
page read and write
clean
330000
heap default
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
36B000
unkown
page read and write
clean
2330000
unkown
page read and write
clean
2C9000
unkown
page read and write
clean
2D8000
unkown
page read and write
clean
2A80000
heap private
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
1F80000
heap private
page read and write
clean
39C000
unkown
page read and write
clean
2BB000
unkown
page read and write
clean
A80000
unkown image
page readonly
clean
2388000
unkown
page read and write
clean
There are 245 hidden memdumps, click here to show them.