IOC Report

loading gif

Files

File Path
Type
Category
Malicious
474556085436219490680.xlsb
Microsoft Excel 2007+
initial sample
malicious
C:\ProgramData\UXcqTE.rtf
HTML document, ASCII text, with very long lines, with CRLF line terminators
dropped
malicious
C:\Users\user\Desktop\~$474556085436219490680.xlsb
data
dropped
malicious
C:\ProgramData\VNsYnsilCvEhxr.txt
ASCII text, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\Q2W5VWUFL5VCMQ7JQPETG3CCTYX72Z4R25PDG[1].txt
ASCII text, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\5EBBEF1D.png
PNG image data, 238 x 337, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\8150A08C.png
PNG image data, 298 x 42, 8-bit/color RGB, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Temp\2D67.tmp
Microsoft Excel 2007+
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
"C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /automation -Embedding
malicious
C:\Windows\System32\wbem\WMIC.exe
wmic process call create "mshta C:\ProgramData\UXcqTE.rtf"
malicious
C:\Windows\System32\mshta.exe
mshta C:\ProgramData\UXcqTE.rtf
clean

URLs

Name
IP
Malicious
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
unknown
clean
http://www.windows.com/pctv.
unknown
clean
http://investor.msn.com
unknown
clean
http://www.msnbc.com/news/ticker.txt
unknown
clean
http://www.%s.comPA
unknown
clean
http://www.icra.org/vocabulary/.
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
http://132.148.135.183:8080/Q2W5VWUFL5VCMQ7JQPETG3CCTYX72Z4R25PDG
132.148.135.183
clean
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
unknown
clean
http://www.hotmail.com/oe
unknown
clean
http://servername/isapibackend.dll
unknown
clean
http://investor.msn.com/
unknown
clean
There are 2 hidden URLs, click here to show them.

IPs

IP
Domain
Country
Malicious
132.148.135.183
unknown
United States
clean

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
*o'
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel
MTTT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\2CDAB
2CDAB
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
VBAFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
hv'
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
ProductNonBootFilesIntl_1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
OriginalAttachmentPath
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
TemporaryAttachmentName
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109A10090400100000000F01FEC\Usage
OutlookMAPI2Intl_1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Security\Trusted Documents
LastPurgeTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
EXCELFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
ProductNonBootFilesIntl_1033
clean
There are 7 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
B50000
unkown image
page readonly
clean
60000
unkown image
page readonly
clean
1F7F000
heap private
page read and write
clean
5D0000
unkown image
page readonly
clean
2030000
unkown
page read and write
clean
2940000
unkown
page read and write
clean
203C000
unkown
page read and write
clean
2BF000
unkown
page read and write
clean
4050000
heap private
page read and write
clean
3E6000
unkown
page read and write
clean
1F50000
unkown image
page readonly
clean
2AE7000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
344000
heap default
page read and write
clean
30000
unkown image
page readonly
clean
2084000
unkown
page read and write
clean
30FF000
stack
page read and write
clean
64EF000
stack
page read and write
clean
74E000
stack
page read and write
clean
3DA0000
unkown
page read and write
clean
2BBF000
stack
page read and write
clean
3210000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
51A000
heap private
page read and write
clean
830000
unkown image
page readonly
clean
2800000
heap private
page read and write
clean
2AE1000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
1B70000
unkown image
page readonly
clean
288F000
stack
page read and write
clean
2BF000
unkown
page read and write
clean
28B000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
2AE5000
unkown
page read and write
clean
2BF000
unkown
page read and write
clean
9B0000
unkown image
page readonly
clean
2BF000
unkown
page read and write
clean
1FD0000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
3D7B000
unkown
page read and write
clean
2976000
unkown
page read and write
clean
2FC5000
heap private
page read and write
clean
366000
unkown
page read and write
clean
39A000
heap default
page read and write
clean
3D72000
unkown
page read and write
clean
459000
unkown
page read and write
clean
2068000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
3D70000
unkown
page read and write
clean
2AE0000
unkown
page read and write
clean
1F35000
heap private
page read and write
clean
2150000
unkown image
page readonly
clean
366000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
3D5F000
unkown
page read and write
clean
3C10000
heap private
page read and write
clean
205C000
unkown
page read and write
clean
2AE3000
unkown
page read and write
clean
50F000
stack
page read and write
clean
1FC8000
unkown
page read and write
clean
3D90000
unkown
page read and write
clean
2AE9000
unkown
page read and write
clean
200C000
unkown
page read and write
clean
2000000
unkown
page read and write
clean
2E2000
unkown
page read and write
clean
3D54000
unkown
page read and write
clean
5B32000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
2230000
heap private
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
5E0000
unkown image
page readonly
clean
3E90000
heap private
page read and write
clean
298000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
1FF8000
unkown
page read and write
clean
2EE000
heap default
page read and write
clean
2AEC000
unkown
page read and write
clean
16D000
unkown
page read and write
clean
403F000
stack
page read and write
clean
7EFE0000
unkown image
page readonly
clean
289000
unkown
page read and write
clean
2710000
heap private
page read and write
clean
41F000
unkown
page read and write
clean
1EA0000
heap private
page read and write
clean
2235000
heap private
page read and write
clean
459000
unkown
page read and write
clean
402000
unkown
page read and write
clean
237000
heap default
page read and write
clean
5742000
unkown image
page read and write
clean
218F000
stack
page read and write
clean
280000
unkown
page read and write
clean
1FE8000
unkown
page read and write
clean
298000
unkown
page read and write
clean
30FF000
stack
page read and write
clean
26D000
heap default
page read and write
clean
2D4000
unkown
page read and write
clean
459000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
2E4000
unkown
page read and write
clean
1FDC000
unkown
page read and write
clean
26E000
heap default
page read and write
clean
510000
heap private
page read and write
clean
412000
unkown
page read and write
clean
444000
heap private
page read and write
clean
43E000
unkown
page read and write
clean
2A60000
heap private
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
1A6000
unkown
page read and write
clean
404000
unkown
page read and write
clean
200000
unkown image
page read and write
clean
2060000
heap private
page read and write
clean
2BA000
unkown
page read and write
clean
2048000
unkown
page read and write
clean
450000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
3B0000
unkown
page read and write
clean
1F76000
heap private
page read and write
clean
204C000
unkown
page read and write
clean
1E0000
heap private
page read and write
clean
25A0000
heap private
page read and write
clean
440000
heap private
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
3F9000
unkown
page read and write
clean
2038000
unkown
page read and write
clean
276000
heap default
page read and write
clean
3D58000
unkown
page read and write
clean
2B7000
heap default
page read and write
clean
43E000
unkown
page read and write
clean
3D74000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
230000
heap default
page read and write
clean
3D50000
unkown
page read and write
clean
1FE4000
unkown
page read and write
clean
2080000
unkown
page read and write
clean
1FF0000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
226B000
heap private
page read and write
clean
2CF0000
unkown
page read and write
clean
3D63000
unkown
page read and write
clean
1F80000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
4320000
unkown
page read and write
clean
40D000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
2805000
heap private
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
20D0000
heap private
page read and write
clean
416000
unkown
page read and write
clean
2FAE000
stack
page read and write
clean
2D2000
unkown
page read and write
clean
1FEC000
unkown
page read and write
clean
1D0000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
1E4000
heap private
page read and write
clean
2BA000
unkown
page read and write
clean
459000
unkown
page read and write
clean
41A0000
heap private
page read and write
clean
2FFB000
heap private
page read and write
clean
40000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
2060000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
1FE0000
unkown
page read and write
clean
2BA000
unkown
page read and write
clean
3D88000
unkown
page read and write
clean
2AE4000
unkown
page read and write
clean
3CD0000
heap private
page read and write
clean
70000
unkown image
page read and write
clean
397000
heap default
page read and write
clean
2008000
unkown
page read and write
clean
41D000
unkown
page read and write
clean
330000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
2AE2000
unkown
page read and write
clean
51D000
heap private
page read and write
clean
2640000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
230000
heap default
page read and write
clean
BDF000
stack
page read and write
clean
25C0000
unkown image
page readonly
clean
440000
unkown
page read and write
clean
261E000
stack
page read and write
clean
3D76000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
1F30000
heap private
page read and write
clean
298000
unkown
page read and write
clean
20D4000
heap private
page read and write
clean
3D6B000
unkown
page read and write
clean
43E000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
2AE8000
unkown
page read and write
clean
42A0000
heap private
page read and write
clean
2F7F000
stack
page read and write
clean
10000
unkown image
page read and write
clean
6BF000
stack
page read and write
clean
1F94000
heap private
page read and write
clean
330000
unkown
page read and write
clean
2014000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
27B000
heap default
page read and write
clean
2CED000
stack
page read and write
clean
3D5C000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
423000
unkown
page read and write
clean
2AE6000
unkown
page read and write
clean
1FF4000
unkown
page read and write
clean
2520000
heap private
page read and write
clean
1FCC000
unkown
page read and write
clean
359000
heap default
page read and write
clean
2004000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
27B000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
2019000
unkown
page read and write
clean
3D82000
unkown
page read and write
clean
2040000
unkown
page read and write
clean
2029000
unkown
page read and write
clean
2AEA000
unkown
page read and write
clean
298000
unkown
page read and write
clean
2620000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
456000
unkown
page read and write
clean
1F60000
unkown image
page read and write
clean
10000
unkown image
page read and write
clean
3AA0000
heap private
page read and write
clean
442000
unkown
page read and write
clean
1FD0000
heap private
page read and write
clean
20000
unkown image
page read and write
clean
237000
heap default
page read and write
clean
2B0000
heap default
page read and write
clean
3CD5000
heap private
page read and write
clean
2FC0000
heap private
page read and write
clean
58F000
stack
page read and write
clean
1FD8000
unkown
page read and write
clean
288000
unkown
page read and write
clean
3D79000
unkown
page read and write
clean
2AEB000
unkown
page read and write
clean
35F0000
unkown image
page readonly
clean
1F6B000
heap private
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
374000
heap default
page read and write
clean
2074000
unkown
page read and write
clean
1F90000
heap private
page read and write
clean
28A000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
25B0000
unkown image
page readonly
clean
33F7000
unkown image
page readonly
clean
43C000
unkown
page read and write
clean
2070000
unkown
page read and write
clean
2BF000
unkown
page read and write
clean
28C0000
heap private
page read and write
clean
1F9B000
heap private
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
12A000
unkown
page read and write
clean
29DF000
stack
page read and write
clean
80000
unkown
page read and write
clean
2850000
heap private
page read and write
clean
514000
heap private
page read and write
clean
2010000
unkown
page read and write
clean
9C0000
unkown image
page readonly
clean
2064000
unkown
page read and write
clean
281F000
stack
page read and write
clean
2BF000
unkown
page read and write
clean
There are 256 hidden memdumps, click here to show them.