IOC Report

loading gif

Files

File Path
Type
Category
Malicious
03332955311591163552.xlsb
Microsoft Excel 2007+
initial sample
malicious
C:\ProgramData\EcsbNSOxkInoaK.rtf
HTML document, ASCII text, with very long lines, with CRLF line terminators
dropped
malicious
C:\Users\user\Desktop\~$03332955311591163552.xlsb
data
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\7204226A.png
PNG image data, 224 x 317, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\72E292CD.png
PNG image data, 256 x 42, 8-bit/color RGB, non-interlaced
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
"C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /automation -Embedding
malicious
C:\Windows\System32\wbem\WMIC.exe
wmic process call create "mshta C:\ProgramData\EcsbNSOxkInoaK.rtf"
malicious
C:\Windows\System32\mshta.exe
mshta C:\ProgramData\EcsbNSOxkInoaK.rtf
clean

URLs

Name
IP
Malicious
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
unknown
clean
http://www.windows.com/pctv.
unknown
clean
http://investor.msn.com
unknown
clean
http://www.msnbc.com/news/ticker.txt
unknown
clean
http://www.%s.comPA
unknown
clean
http://www.icra.org/vocabulary/.
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
unknown
clean
http://www.hotmail.com/oe
unknown
clean
http://servername/isapibackend.dll
unknown
clean
http://investor.msn.com/
unknown
clean
There are 1 hidden URLs, click here to show them.

IPs

IP
Domain
Country
Malicious
136.144.181.174
unknown
Netherlands
clean

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
}|*
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel
MTTT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\2D73C
2D73C
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
VBAFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
;$*
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
ProductNonBootFilesIntl_1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Security\Trusted Documents
LastPurgeTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
EXCELFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
ProductNonBootFilesIntl_1033
clean
There are 4 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
3D4000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
3BA000
unkown
page read and write
clean
2770000
unkown
page read and write
clean
2EF3000
unkown
page read and write
clean
27CC000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
35F0000
heap private
page read and write
clean
F0000
unkown
page read and write
clean
27C8000
unkown
page read and write
clean
216000
heap default
page read and write
clean
3890000
unkown image
page readonly
clean
250000
heap private
page read and write
clean
212F000
stack
page read and write
clean
5488000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
3B9000
unkown
page read and write
clean
27E8000
unkown
page read and write
clean
24A000
unkown
page read and write
clean
307E000
stack
page read and write
clean
1340000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
3E7000
unkown
page read and write
clean
20000
unkown image
page read and write
clean
B1E000
stack
page read and write
clean
398000
unkown
page read and write
clean
2755000
heap private
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
2860000
unkown
page read and write
clean
3FD000
unkown
page read and write
clean
1A0000
heap private
page read and write
clean
401000
unkown
page read and write
clean
2A50000
heap private
page read and write
clean
D0000
unkown image
page readonly
clean
2819000
unkown
page read and write
clean
2850000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
2F69000
heap private
page read and write
clean
2E0F000
stack
page read and write
clean
27F8000
unkown
page read and write
clean
416000
unkown
page read and write
clean
419000
unkown
page read and write
clean
27D0000
unkown
page read and write
clean
27BC000
unkown
page read and write
clean
330000
heap default
page read and write
clean
2F65000
heap private
page read and write
clean
4C20000
heap private
page read and write
clean
3BA000
unkown
page read and write
clean
1C50000
unkown image
page readonly
clean
2F60000
heap private
page read and write
clean
54B1000
unkown
page read and write
clean
466000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
399000
unkown
page read and write
clean
1FE0000
heap private
page read and write
clean
3C70000
unkown
page read and write
clean
2740000
unkown image
page readonly
clean
400000
unkown
page read and write
clean
2E70000
heap private
page read and write
clean
398000
unkown
page read and write
clean
3D6000
unkown
page read and write
clean
27E4000
unkown
page read and write
clean
80000
heap private
page read and write
clean
548D000
unkown
page read and write
clean
2F00000
unkown
page read and write
clean
22E5000
heap private
page read and write
clean
292000
heap default
page read and write
clean
2960000
unkown image
page readonly
clean
36E000
heap default
page read and write
clean
3CD000
unkown
page read and write
clean
400000
unkown
page read and write
clean
5491000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
54CE000
unkown
page read and write
clean
200000
heap default
page read and write
clean
3BA000
unkown
page read and write
clean
27DC000
unkown
page read and write
clean
1A6000
unkown
page read and write
clean
2D0000
unkown
page read and write
clean
54BE000
unkown
page read and write
clean
56FF000
stack
page read and write
clean
370000
unkown
page read and write
clean
2810000
heap private
page read and write
clean
A5F000
stack
page read and write
clean
34C5000
heap private
page read and write
clean
2344000
heap private
page read and write
clean
2A60000
unkown image
page readonly
clean
2EF9000
unkown
page read and write
clean
3A77000
unkown image
page readonly
clean
2C4000
heap default
page read and write
clean
3E4000
unkown
page read and write
clean
2864000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
282C000
unkown
page read and write
clean
530000
unkown image
page readonly
clean
27FC000
unkown
page read and write
clean
3D2000
unkown
page read and write
clean
98F000
stack
page read and write
clean
2EF0000
unkown
page read and write
clean
3A6000
unkown
page read and write
clean
2326000
heap private
page read and write
clean
3D2000
unkown
page read and write
clean
5000000
heap private
page read and write
clean
27F0000
unkown
page read and write
clean
27B8000
unkown
page read and write
clean
419000
unkown
page read and write
clean
337E000
stack
page read and write
clean
38B000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
27F4000
unkown
page read and write
clean
20D000
heap default
page read and write
clean
3BA000
unkown
page read and write
clean
2ABB000
heap private
page read and write
clean
6B12000
unkown image
page readonly
clean
11B0000
unkown image
page readonly
clean
54A7000
unkown
page read and write
clean
33B6000
unkown
page read and write
clean
4F0000
heap private
page read and write
clean
3E3000
unkown
page read and write
clean
549E000
unkown
page read and write
clean
4E10000
heap private
page read and write
clean
2EFA000
unkown
page read and write
clean
6C0000
unkown image
page readonly
clean
27D4000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
2EF1000
unkown
page read and write
clean
2C50000
heap private
page read and write
clean
2EF5000
unkown
page read and write
clean
3BA000
unkown
page read and write
clean
2874000
unkown
page read and write
clean
400000
unkown
page read and write
clean
3FC000
unkown
page read and write
clean
3BA000
unkown
page read and write
clean
207000
heap default
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
54AA000
unkown
page read and write
clean
E0000
unkown image
page read and write
clean
2750000
unkown image
page read and write
clean
3325000
heap private
page read and write
clean
37B000
unkown
page read and write
clean
400000
unkown
page read and write
clean
2EF6000
unkown
page read and write
clean
2800000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
40000
unkown image
page readonly
clean
4BE000
stack
page read and write
clean
2809000
unkown
page read and write
clean
3FD000
unkown
page read and write
clean
3BF000
unkown
page read and write
clean
2EFC000
unkown
page read and write
clean
11A0000
unkown image
page readonly
clean
218000
heap default
page read and write
clean
54B7000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
1D7000
heap default
page read and write
clean
30000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
388000
unkown
page read and write
clean
54A5000
unkown
page read and write
clean
180000
unkown image
page read and write
clean
2EF8000
unkown
page read and write
clean
27C0000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
2EF7000
unkown
page read and write
clean
150000
unkown
page read and write
clean
28E0000
heap private
page read and write
clean
2E9000
heap default
page read and write
clean
2A85000
heap private
page read and write
clean
2804000
unkown
page read and write
clean
2858000
unkown
page read and write
clean
398000
unkown
page read and write
clean
549A000
unkown
page read and write
clean
1A4000
heap private
page read and write
clean
2870000
unkown
page read and write
clean
3FD000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
231B000
heap private
page read and write
clean
22E0000
heap private
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
4CF0000
heap private
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
35EE000
stack
page read and write
clean
2A50000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
278B000
heap private
page read and write
clean
32FF000
stack
page read and write
clean
10000
unkown image
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
380000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
2830000
unkown
page read and write
clean
23E000
heap default
page read and write
clean
1020000
unkown image
page readonly
clean
2A80000
heap private
page read and write
clean
3D70000
unkown image
page readonly
clean
2750000
heap private
page read and write
clean
4F4000
heap private
page read and write
clean
28E4000
heap private
page read and write
clean
430000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
2838000
unkown
page read and write
clean
1D0000
heap default
page read and write
clean
6722000
unkown image
page read and write
clean
306000
unkown
page read and write
clean
6B0000
unkown image
page readonly
clean
284C000
unkown
page read and write
clean
4B40000
heap private
page read and write
clean
2854000
unkown
page read and write
clean
232F000
heap private
page read and write
clean
234B000
heap private
page read and write
clean
3BF000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
2820000
unkown
page read and write
clean
2240000
heap private
page read and write
clean
5480000
unkown
page read and write
clean
5080000
unkown
page read and write
clean
419000
unkown
page read and write
clean
38A000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
2828000
unkown
page read and write
clean
337000
heap default
page read and write
clean
283C000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
2340000
heap private
page read and write
clean
2EF4000
unkown
page read and write
clean
2BFE000
stack
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
3C5000
unkown
page read and write
clean
4FA000
heap private
page read and write
clean
54A3000
unkown
page read and write
clean
84000
heap private
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
388E000
stack
page read and write
clean
389000
unkown
page read and write
clean
12D000
unkown
page read and write
clean
3C2000
unkown
page read and write
clean
75FF000
stack
page read and write
clean
34CD000
stack
page read and write
clean
7EFE0000
unkown image
page readonly
clean
40000
unkown image
page readonly
clean
54A0000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
2EFB000
unkown
page read and write
clean
3380000
unkown
page read and write
clean
27E0000
unkown
page read and write
clean
2130000
heap private
page read and write
clean
398000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
4FD000
heap private
page read and write
clean
2890000
unkown image
page readonly
clean
419000
unkown
page read and write
clean
2EF2000
unkown
page read and write
clean
3320000
heap private
page read and write
clean
3BF000
unkown
page read and write
clean
34C0000
heap private
page read and write
clean
27D8000
unkown
page read and write
clean
3DC000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
2EFE000
stack
page read and write
clean
3DF000
unkown
page read and write
clean
There are 256 hidden memdumps, click here to show them.