IOC Report

loading gif

Files

File Path
Type
Category
Malicious
03332955311591163552.xlsb
Microsoft Excel 2007+
initial sample
malicious
C:\ProgramData\EcsbNSOxkInoaK.rtf
HTML document, ASCII text, with very long lines, with CRLF line terminators
dropped
malicious
C:\Users\user\Desktop\~$03332955311591163552.xlsb
data
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\7204226A.png
PNG image data, 224 x 317, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\72E292CD.png
PNG image data, 256 x 42, 8-bit/color RGB, non-interlaced
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
"C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /automation -Embedding
malicious
C:\Windows\System32\wbem\WMIC.exe
wmic process call create "mshta C:\ProgramData\EcsbNSOxkInoaK.rtf"
malicious
C:\Windows\System32\mshta.exe
mshta C:\ProgramData\EcsbNSOxkInoaK.rtf
clean

URLs

Name
IP
Malicious
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
unknown
clean
http://www.windows.com/pctv.
unknown
clean
http://investor.msn.com
unknown
clean
http://www.msnbc.com/news/ticker.txt
unknown
clean
http://www.%s.comPA
unknown
clean
http://www.icra.org/vocabulary/.
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
unknown
clean
http://www.hotmail.com/oe
unknown
clean
http://servername/isapibackend.dll
unknown
clean
http://investor.msn.com/
unknown
clean
There are 1 hidden URLs, click here to show them.

IPs

IP
Domain
Country
Malicious
136.144.181.174
unknown
Netherlands
clean

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
}|*
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel
MTTT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\2D73C
2D73C
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
VBAFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
;$*
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
ProductNonBootFilesIntl_1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Security\Trusted Documents
LastPurgeTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
EXCELFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
ProductNonBootFilesIntl_1033
clean
There are 4 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
3D4000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
3BA000
unkown
page read and write
clean
2770000
unkown
page read and write
clean
2EF3000
unkown
page read and write
clean
27CC000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
35F0000
heap private
page read and write
clean
F0000
unkown
page read and write
clean
27C8000
unkown
page read and write
clean
216000
heap default
page read and write
clean
3890000
unkown image
page readonly
clean
250000
heap private
page read and write
clean
212F000
stack
page read and write
clean
5488000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
3B9000
unkown
page read and write
clean
27E8000
unkown
page read and write
clean
24A000
unkown
page read and write
clean
307E000
stack
page read and write
clean
1340000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
3E7000
unkown
page read and write
clean
20000
unkown image
page read and write
clean
B1E000
stack
page read and write
clean
398000
unkown
page read and write
clean
2755000
heap private
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
2860000
unkown
page read and write
clean
3FD000
unkown
page read and write
clean
1A0000
heap private
page read and write
clean
401000
unkown
page read and write
clean
2A50000
heap private
page read and write
clean
D0000
unkown image
page readonly
clean
2819000
unkown
page read and write
clean
2850000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
2F69000
heap private
page read and write
clean