IOC Report

loading gif

Files

File Path
Type
Category
Malicious
Sale-8799306.xlsb
Microsoft Excel 2007+
initial sample
malicious
C:\ProgramData\CjBEfxIRZH.rtf
HTML document, ASCII text, with very long lines, with CRLF line terminators
dropped
malicious
C:\Users\user\Desktop\~$Sale-8799306.xlsb
data
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\55A75020.png
PNG image data, 275 x 49, 8-bit/color RGB, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\D68BD1A1.png
PNG image data, 225 x 317, 8-bit/color RGBA, non-interlaced
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
"C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /automation -Embedding
malicious
C:\Windows\System32\wbem\WMIC.exe
wmic process call create "mshta C:\ProgramData\CjBEfxIRZH.rtf"
malicious
C:\Windows\System32\mshta.exe
mshta C:\ProgramData\CjBEfxIRZH.rtf
clean

URLs

Name
IP
Malicious
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
unknown
clean
http://www.windows.com/pctv.
unknown
clean
http://investor.msn.com
unknown
clean
http://www.msnbc.com/news/ticker.txt
unknown
clean
http://www.%s.comPA
unknown
clean
http://www.icra.org/vocabulary/.
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
unknown
clean
http://www.hotmail.com/oe
unknown
clean
http://servername/isapibackend.dll
unknown
clean
http://investor.msn.com/
unknown
clean
There are 1 hidden URLs, click here to show them.

IPs

IP
Domain
Country
Malicious
136.144.181.174
unknown
Netherlands
clean

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
.a,
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel
MTTT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\2CFCD
2CFCD
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
VBAFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
mh,
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
ProductNonBootFilesIntl_1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Security\Trusted Documents
LastPurgeTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
EXCELFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
ProductNonBootFilesIntl_1033
clean
There are 4 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
106000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
3E2000
unkown
page read and write
clean
380000
unkown image
page readonly
clean
2CA4000
unkown
page read and write
clean
2CA0000
unkown
page read and write
clean
2B04000
heap private
page read and write
clean
2CA5000
unkown
page read and write
clean
4FBE000
unkown
page read and write
clean
233F000
heap private
page read and write
clean
2BC4000
unkown
page read and write
clean
2D90000
heap private
page read and write
clean
4F84000
unkown
page read and write
clean
2CA9000
unkown
page read and write
clean
27F0000
heap private
page read and write
clean
12F0000
unkown image
page readonly
clean
2BD4000
unkown
page read and write
clean
50A000
heap private
page read and write
clean
52B0000
heap private
page read and write
clean
7EFE0000
unkown image
page readonly
clean
3CD000
heap default
page read and write
clean
296000
unkown
page read and write
clean
2BB0000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
2BD9000
unkown
page read and write
clean
1EC0000
heap private
page read and write
clean
2CA6000
unkown
page read and write
clean
1C8000
unkown
page read and write
clean
4F8E000
unkown
page read and write
clean
2C00000
unkown
page read and write
clean
4F93000
unkown
page read and write
clean
5330000
heap private
page read and write
clean
204000
unkown
page read and write
clean
6F72000
unkown image
page readonly
clean
2BF0000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
3DD0000
unkown
page read and write
clean
2C28000
unkown
page read and write
clean
3250000
heap private
page read and write
clean
1C8000
unkown
page read and write
clean
340F000
stack
page read and write
clean
630000
heap private
page read and write
clean
500000
unkown image
page readonly
clean
2BC8000
unkown
page read and write
clean
2BA4000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
429000
unkown
page read and write
clean
3255000
heap private
page read and write
clean
2354000
heap private
page read and write
clean
160000
heap default
page read and write
clean
2BF8000
unkown
page read and write
clean
2AC0000
unkown image
page readonly
clean
2CAB000
unkown
page read and write
clean
22F5000
heap private
page read and write
clean
20B000
unkown
page read and write
clean
2C44000
unkown
page read and write
clean
369000
heap default
page read and write
clean
4EF5000
heap private
page read and write
clean
2C34000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
40000
unkown image
page readonly
clean
1ED000
unkown
page read and write
clean
1EF000
unkown
page read and write
clean
4FA7000
unkown
page read and write
clean
360000
unkown image
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
2C20000
heap private
page read and write
clean
4F87000
unkown
page read and write
clean
2CA3000
unkown
page read and write
clean
3DB000
heap default
page read and write
clean
5530000
heap private
page read and write
clean
30000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
79F000
stack
page read and write
clean
2C24000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
2A40000
heap private
page read and write
clean
1EF000
unkown
page read and write
clean
3ED000
unkown
page read and write
clean
3B6000
unkown
page read and write
clean
2CA2000
unkown
page read and write
clean
71F000
stack
page read and write
clean
3C9000
unkown
page read and write
clean
4F9A000
unkown
page read and write
clean
140000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
2B90000
unkown
page read and write
clean
2C08000
unkown
page read and write
clean
136000
unkown
page read and write
clean
2640000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
3275000
heap private
page read and write
clean
429000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
397000
heap default
page read and write
clean
223E000
stack
page read and write
clean
1B0000
unkown
page read and write
clean
2B9C000
unkown
page read and write
clean
1EF000
unkown
page read and write
clean
40E000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
4F97000
unkown
page read and write
clean
50D000
heap private
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
2A20000
unkown image
page read and write
clean
2BAC000
unkown
page read and write
clean
D0F000
stack
page read and write
clean
500000
heap private
page read and write
clean
287000
heap default
page read and write
clean
2BA8000
unkown
page read and write
clean
56E0000
heap private
page read and write
clean
40E000
unkown
page read and write
clean
20B000
unkown
page read and write
clean
510000
unkown image
page readonly
clean
2BB8000
unkown
page read and write
clean
4F7F000
unkown
page read and write
clean
504000
heap private
page read and write
clean
3220000
heap private
page read and write
clean
232B000
heap private
page read and write
clean
2B8C000
unkown
page read and write
clean
4F91000
unkown
page read and write
clean
3279000
heap private
page read and write
clean
1470000
unkown image
page readonly
clean
2336000
heap private
page read and write
clean
634000
heap private
page read and write
clean
38EF000
stack
page read and write
clean
4FA1000
unkown
page read and write
clean
3EF000
unkown
page read and write
clean
2C30000
unkown
page read and write
clean
3DD000
unkown
page read and write
clean
2C0C000
unkown
page read and write
clean
29D000
unkown
page read and write
clean
1EA000
unkown
page read and write
clean
2CA8000
unkown
page read and write
clean
EA000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
1EB0000
unkown image
page read and write
clean
2350000
heap private
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
1C8000
unkown
page read and write
clean
2B88000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
2BA0000
unkown
page read and write
clean
1ED000
unkown
page read and write
clean
3D5000
unkown
page read and write
clean
344000
heap default
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
20B000
unkown
page read and write
clean
2BB4000
unkown
page read and write
clean
5760000
unkown
page read and write
clean
429000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
4EF0000
heap private
page read and write
clean
390000
heap default
page read and write
clean
20000
unkown image
page read and write
clean
2240000
heap private
page read and write
clean
3E6000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
2C40000
unkown
page read and write
clean
280000
heap default
page read and write
clean
1BB000
unkown
page read and write
clean
20FF000
stack
page read and write
clean
40E000
unkown
page read and write
clean
2DCB000
heap private
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
3D6000
heap default
page read and write
clean
30000
unkown image
page readonly
clean
202000
unkown
page read and write
clean
3BD7000
unkown image
page readonly
clean
2A40000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
2BE9000
unkown
page read and write
clean
1AA0000
unkown image
page readonly
clean
2CAC000
unkown
page read and write
clean
2BE000
heap default
page read and write
clean
374000
heap private
page read and write
clean
2A10000
unkown image
page readonly
clean
1EA000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
2CA7000
unkown
page read and write
clean
1C8000
unkown
page read and write
clean
1B9000
unkown
page read and write
clean
39F0000
unkown image
page readonly
clean
1B8000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
19E000
heap default
page read and write
clean
4F76000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
1BA000
unkown
page read and write
clean
380000
unkown
page read and write
clean
429000
unkown
page read and write
clean
1480000
unkown image
page readonly
clean
1EA000
unkown
page read and write
clean
60000
unkown image
page readonly
clean
527E000
stack
page read and write
clean
214000
unkown
page read and write
clean
3270000
heap private
page read and write
clean
2BD0000
unkown
page read and write
clean
4020000
unkown image
page readonly
clean
412000
unkown
page read and write
clean
30E0000
unkown
page read and write
clean
2CA1000
unkown
page read and write
clean
426000
unkown
page read and write
clean
2B98000
unkown
page read and write
clean
2BC0000
unkown
page read and write
clean
2C1E000
stack
page read and write
clean
2C20000
unkown
page read and write
clean
2BCC000
unkown
page read and write
clean
260000
unkown
page read and write
clean
328B000
heap private
page read and write
clean
1F50000
heap private
page read and write
clean
D0000
unkown
page read and write
clean
1FD0000
heap private
page read and write
clean
30D6000
unkown
page read and write
clean
4F70000
unkown
page read and write
clean
321F000
stack
page read and write
clean
3225000
heap private
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
321000
heap default
page read and write
clean
1AB000
unkown
page read and write
clean
6B82000
unkown image
page read and write
clean
167000
heap default
page read and write
clean
4FAE000
unkown
page read and write
clean
4F95000
unkown
page read and write
clean
1E20000
heap private
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
1ED000
unkown
page read and write
clean
370000
heap private
page read and write
clean
376D000
stack
page read and write
clean
2AD0000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
358F000
stack
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
1DA0000
unkown
page read and write
clean
2C1C000
unkown
page read and write
clean
30A0000
unkown
page read and write
clean
50E0000
heap private
page read and write
clean
79AF000
stack
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
345F000
stack
page read and write
clean
29AE000
stack
page read and write
clean
3F3000
unkown
page read and write
clean
2C80000
unkown image
page readonly
clean
3D2000
unkown
page read and write
clean
40C000
unkown
page read and write
clean
2B00000
heap private
page read and write
clean
22F0000
heap private
page read and write
clean
4DF0000
heap private
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
1610000
unkown image
page readonly
clean
212000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
2CAA000
unkown
page read and write
clean
410000
unkown
page read and write
clean
1E00000
unkown
page read and write
clean
235B000
heap private
page read and write
clean
2BFC000
unkown
page read and write
clean
2D95000
heap private
page read and write
clean
There are 254 hidden memdumps, click here to show them.