IOC Report

loading gif

Files

File Path
Type
Category
Malicious
BookingXConfirm-11401.xlsb
Microsoft Excel 2007+
initial sample
malicious
C:\ProgramData\BnnsIhc.rtf
HTML document, ASCII text, with very long lines, with CRLF line terminators
dropped
malicious
C:\Users\user\Desktop\~$BookingXConfirm-11401.xlsb
data
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\3B01B891.png
PNG image data, 292 x 49, 8-bit/color RGB, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\B4C9255E.png
PNG image data, 237 x 336, 8-bit/color RGBA, non-interlaced
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
"C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /automation -Embedding
malicious
C:\Windows\System32\wbem\WMIC.exe
wmic.exe process call create 'mshta C:\\ProgramData\BnnsIhc.rtf'
malicious
C:\Windows\System32\mshta.exe
mshta C:\\ProgramData\BnnsIhc.rtf
clean

URLs

Name
IP
Malicious
http://103.117.180.99:8080/PJ3ZQWVJPYCYDCA9A6Q2Y6YA
103.117.180.99
malicious
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
unknown
clean
http://www.windows.com/pctv.
unknown
clean
http://investor.msn.com
unknown
clean
http://www.msnbc.com/news/ticker.txt
unknown
clean
http://www.%s.comPA
unknown
clean
http://www.icra.org/vocabulary/.
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
unknown
clean
http://www.hotmail.com/oe
unknown
clean
http://servername/isapibackend.dll
unknown
clean
http://investor.msn.com/
unknown
clean
There are 2 hidden URLs, click here to show them.

IPs

IP
Domain
Country
Malicious
103.117.180.99
unknown
India
malicious

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
? .
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel
MTTT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\2D22D
2D22D
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
VBAFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
;g.
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
ProductNonBootFilesIntl_1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Security\Trusted Documents
LastPurgeTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
EXCELFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
ProductNonBootFilesIntl_1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
clean
There are 4 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
524A000
unkown
page read and write
clean
25C4000
unkown
page read and write
clean
2EB000
unkown
page read and write
clean
31A000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
2905000
heap private
page read and write
clean
2A97000
unkown
page read and write
clean
25D0000
unkown
page read and write
clean
104000
heap private
page read and write
clean
4E30000
unkown
page read and write
clean
F90000
unkown image
page readonly
clean
53FB000
heap private
page read and write
clean
2ED000
unkown
page read and write
clean
31F000
unkown
page read and write
clean
1DD000
heap default
page read and write
clean
2E8000
unkown
page read and write
clean
2638000
unkown
page read and write
clean
25F9000
unkown
page read and write
clean
344000
unkown
page read and write
clean
2DB000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
25A8000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
2A9A000
unkown
page read and write
clean
390000
unkown
page read and write
clean
2610000
unkown
page read and write
clean
2A93000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
457000
heap default
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
216000
heap private
page read and write
clean
31D5000
heap private
page read and write
clean
2630000
unkown
page read and write
clean
290000
heap default
page read and write
clean
24D0000
heap private
page read and write
clean
C0000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
280000
unkown
page read and write
clean
5243000
unkown
page read and write
clean
25D4000
unkown
page read and write
clean
2F9000
unkown
page read and write
clean
10A000
heap private
page read and write
clean
30F6000
unkown
page read and write
clean
1C80000
unkown image
page readonly
clean
234000
heap private
page read and write
clean
2A10000
heap private
page read and write
clean
2D2000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
40000
unkown image
page readonly
clean
A3F000
stack
page read and write
clean
2640000
unkown
page read and write
clean
3B4000
heap private
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
524C000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
1A7000
heap default
page read and write
clean
2E4F000
stack
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
2635000
heap private
page read and write
clean
2930000
heap private
page read and write
clean
31D0000
heap private
page read and write
clean
2520000
unkown image
page readonly
clean
51F000
stack
page read and write
clean
20C0000
heap private
page read and write
clean
2A90000
unkown
page read and write
clean
31F000
unkown
page read and write
clean
10D000
heap private
page read and write
clean
4AB0000
heap private
page read and write
clean
2F4000
unkown
page read and write
clean
2900000
heap private
page read and write
clean
334000
unkown
page read and write
clean
5262000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
1120000
unkown image
page readonly
clean
318F000
stack
page read and write
clean
25E0000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
5254000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
260C000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
2530000
unkown image
page read and write
clean
30C000
unkown
page read and write
clean
26B0000
unkown image
page readonly
clean
308F000
stack
page read and write
clean
B0000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
35D0000
heap private
page read and write
clean
3C6000
unkown
page read and write
clean
2550000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
2E2000
unkown
page read and write
clean
5230000
unkown
page read and write
clean
4F3000
heap default
page read and write
clean
2D5000
unkown
page read and write
clean
2694000
heap private
page read and write
clean
25BC000
unkown
page read and write
clean
2F8000
unkown
page read and write
clean
3B0000
heap private
page read and write
clean
10000
unkown image
page read and write
clean
2658000
unkown
page read and write
clean
2830000
unkown image
page readonly
clean
2840000
unkown image
page readonly
clean
2A92000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
2A98000
unkown
page read and write
clean
1E6000
heap default
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
2720000
unkown image
page readonly
clean
5260000
unkown
page read and write
clean
4CF0000
heap private
page read and write
clean
2A95000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
4A0000
heap private
page read and write
clean
5257000
unkown
page read and write
clean
554000
heap private
page read and write
clean
5269000
unkown
page read and write
clean
334D000
stack
page read and write
clean
2DD000
unkown
page read and write
clean
30C0000
unkown
page read and write
clean
301F000
stack
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
31A000
unkown
page read and write
clean
3230000
heap private
page read and write
clean
1D5000
heap private
page read and write
clean
5277000
unkown
page read and write
clean
31D9000
heap private
page read and write
clean
2690000
heap private
page read and write
clean
5248000
unkown
page read and write
clean
2598000
unkown
page read and write
clean
250000
unkown image
page read and write
clean
1BA000
unkown
page read and write
clean
2F8000
unkown
page read and write
clean
1ED000
heap default
page read and write
clean
25AC000
unkown
page read and write
clean
30BE000
stack
page read and write
clean
21F000
heap private
page read and write
clean
2E3000
unkown
page read and write
clean
31A000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
20B000
heap private
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
2A99000
unkown
page read and write
clean
4C10000
heap private
page read and write
clean
10000
unkown image
page read and write
clean
31A000
unkown
page read and write
clean
6F0000
unkown image
page readonly
clean
48F0000
heap private
page read and write
clean
3235000
heap private
page read and write
clean
100000
heap private
page read and write
clean
525D000
unkown
page read and write
clean
3B40000
unkown image
page readonly
clean
F80000
unkown image
page readonly
clean
2630000
heap private
page read and write
clean
1D0000
heap private
page read and write
clean
31F000
unkown
page read and write
clean
2A94000
unkown
page read and write
clean
202F000
stack
page read and write
clean
2B6000
unkown
page read and write
clean
2D0F000
stack
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
2F0000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
25B0000
unkown
page read and write
clean
550000
heap private
page read and write
clean
55EF000
stack
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
2E6000
unkown
page read and write
clean
25E9000
unkown
page read and write
clean
347000
unkown
page read and write
clean
25D8000
unkown
page read and write
clean
519000
heap default
page read and write
clean
2D6000
unkown
page read and write
clean
332000
unkown
page read and write
clean
259C000
unkown
page read and write
clean
31A000
unkown
page read and write
clean
2EA000
unkown
page read and write
clean
2A96000
unkown
page read and write
clean
523D000
unkown
page read and write
clean
2600000
unkown
page read and write
clean
20000
unkown image
page read and write
clean
D0000
unkown image
page readonly
clean
2F4000
unkown
page read and write
clean
2A0000
unkown
page read and write
clean
3947000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
2A9C000
unkown
page read and write
clean
2CE000
heap default
page read and write
clean
23B000
heap private
page read and write
clean
5270000
unkown
page read and write
clean
450000
heap default
page read and write
clean
25DC000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
E00000
unkown image
page readonly
clean
230000
heap private
page read and write
clean
3480000
unkown
page read and write
clean
2E0000
unkown
page read and write
clean
3760000
unkown image
page readonly
clean
E0000
unkown image
page read and write
clean
5246000
unkown
page read and write
clean
250000
unkown
page read and write
clean
B0E000
stack
page read and write
clean
2C9000
unkown
page read and write
clean
297000
heap default
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
25B8000
unkown
page read and write
clean
AD000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
5259000
unkown
page read and write
clean
2608000
unkown
page read and write
clean
560000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
6E0000
unkown image
page readonly
clean
2644000
unkown
page read and write
clean
25B0000
heap private
page read and write
clean
31A000
unkown
page read and write
clean
F0000
unkown
page read and write
clean
277000
unkown
page read and write
clean
1A0000
heap default
page read and write
clean
2870000
unkown
page read and write
clean
266B000
heap private
page read and write
clean
27A0000
heap private
page read and write
clean
525B000
unkown
page read and write
clean
25B4000
unkown
page read and write
clean
25A0000
unkown
page read and write
clean
2618000
unkown
page read and write
clean
261C000
unkown
page read and write
clean
48E000
heap default
page read and write
clean
49F000
stack
page read and write
clean
293B000
heap private
page read and write
clean
2A91000
unkown
page read and write
clean
2040000
heap private
page read and write
clean
2F8000
unkown
page read and write
clean
2A9B000
unkown
page read and write
clean
2F8000
unkown
page read and write
clean
53C0000
heap private
page read and write
clean
588F000
stack
page read and write
clean
25C8000
unkown
page read and write
clean
53C4000
heap private
page read and write
clean
2660000
unkown
page read and write
clean
2634000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
2F7E000
stack
page read and write
clean
2E9000
unkown
page read and write
clean
48F5000
heap private
page read and write
clean
4B30000
heap private
page read and write
clean
2F7F000
stack
page read and write
clean
53E000
heap default
page read and write
clean
25C0000
unkown
page read and write
clean
4A10000
heap private
page read and write
clean
30000
unkown image
page readonly
clean
25E4000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
There are 247 hidden memdumps, click here to show them.