IOC Report

loading gif

Files

File Path
Type
Category
Malicious
Sale-8799306.xlsb
Microsoft Excel 2007+
initial sample
malicious
C:\ProgramData\CjBEfxIRZH.rtf
HTML document, ASCII text, with very long lines, with CRLF line terminators
dropped
malicious
C:\Users\user\Desktop\~$Sale-8799306.xlsb
data
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\55A75020.png
PNG image data, 275 x 49, 8-bit/color RGB, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\D68BD1A1.png
PNG image data, 225 x 317, 8-bit/color RGBA, non-interlaced
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
"C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /automation -Embedding
malicious
C:\Windows\System32\wbem\WMIC.exe
wmic process call create "mshta C:\ProgramData\CjBEfxIRZH.rtf"
malicious
C:\Windows\System32\mshta.exe
mshta C:\ProgramData\CjBEfxIRZH.rtf
clean

URLs

Name
IP
Malicious
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
unknown
clean
http://www.windows.com/pctv.
unknown
clean
http://investor.msn.com
unknown
clean
http://www.msnbc.com/news/ticker.txt
unknown
clean
http://www.%s.comPA
unknown
clean
http://www.icra.org/vocabulary/.
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
unknown
clean
http://www.hotmail.com/oe
unknown
clean
http://servername/isapibackend.dll
unknown
clean
http://investor.msn.com/
unknown
clean
There are 1 hidden URLs, click here to show them.

IPs

IP
Domain
Country
Malicious
136.144.181.174
unknown
Netherlands
clean

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
.a,
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel
MTTT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\2CFCD
2CFCD
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
VBAFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
mh,
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
ProductNonBootFilesIntl_1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Security\Trusted Documents
LastPurgeTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
EXCELFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
ProductNonBootFilesIntl_1033
clean
There are 4 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
106000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
3E2000
unkown
page read and write
clean
380000
unkown image
page readonly
clean
2CA4000
unkown
page read and write
clean
2CA0000
unkown
page read and write
clean
2B04000
heap private
page read and write
clean
2CA5000
unkown
page read and write
clean
4FBE000
unkown
page read and write
clean
233F000
heap private
page read and write
clean
2BC4000
unkown
page read and write
clean
2D90000
heap private
page read and write
clean
4F84000
unkown
page read and write
clean
2CA9000
unkown
page read and write
clean
27F0000
heap private
page read and write
clean
12F0000
unkown image
page readonly
clean
2BD4000
unkown
page read and write
clean
50A000
heap private
page read and write
clean
52B0000
heap private
page read and write
clean
7EFE0000
unkown image
page readonly
clean
3CD000
heap default
page read and write
clean
296000
unkown
page read and write
clean
2BB0000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
2BD9000
unkown
page read and write
clean
1EC0000
heap private
page read and write
clean
2CA6000
unkown
page read and write
clean
1C8000
unkown
page read and write
clean
4F8E000
unkown
page read and write
clean
2C00000
unkown
page read and write
clean
4F93000
unkown
page read and write
clean
5330000
heap private
page read and write
clean
204000
unkown
page read and write
clean
6F72000
unkown image
page readonly
clean
2BF0000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
3DD0000
unkown
page read and write
clean
2C28000
unkown
page read and write
clean
3250000
heap private
page read and write
clean
1C8000
unkown
page read and write
clean
340F000
stack
page read and write
clean