IOC Report

loading gif

Files

File Path
Type
Category
Malicious
7165.xlsb
Microsoft Excel 2007+
initial sample
malicious
C:\ProgramData\HIXhaYv.rtf
HTML document, ASCII text, with very long lines, with CRLF line terminators
dropped
malicious
C:\Users\user\Desktop\~$7165.xlsb
data
dropped
malicious
C:\ProgramData\uLbchwVzJ.txt
ASCII text, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\Q2W5VWUFL5VCMQ7JQPETG3CCTYX72Z4R25PDG[1].txt
ASCII text, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\B1075D7F.png
PNG image data, 256 x 51, 8-bit/color RGB, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\E075974.png
PNG image data, 237 x 336, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Temp\33DC.tmp
Microsoft Excel 2007+
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
"C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /automation -Embedding
malicious
C:\Windows\System32\wbem\WMIC.exe
wmic process call create "mshta C:\ProgramData\HIXhaYv.rtf"
malicious
C:\Windows\System32\mshta.exe
mshta C:\ProgramData\HIXhaYv.rtf
clean

URLs

Name
IP
Malicious
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
unknown
clean
http://www.windows.com/pctv.
unknown
clean
http://investor.msn.com
unknown
clean
http://www.msnbc.com/news/ticker.txt
unknown
clean
http://www.%s.comPA
unknown
clean
http://www.icra.org/vocabulary/.
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
unknown
clean
http://www.hotmail.com/oe
unknown
clean
http://servername/isapibackend.dll
unknown
clean
http://investor.msn.com/
unknown
clean
http://157.245.108.215:8080/Q2W5VWUFL5VCMQ7JQPETG3CCTYX72Z4R25PDG
157.245.108.215
clean
There are 2 hidden URLs, click here to show them.

IPs

IP
Domain
Country
Malicious
157.245.108.215
unknown
United States
clean

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
$i*
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel
MTTT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\2D384
2D384
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
VBAFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
wo*
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
ProductNonBootFilesIntl_1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
OriginalAttachmentPath
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
TemporaryAttachmentName
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109A10090400100000000F01FEC\Usage
OutlookMAPI2Intl_1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Security\Trusted Documents
LastPurgeTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
EXCELFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
ProductNonBootFilesIntl_1033
clean
There are 7 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
264000
heap private
page read and write
clean
408000
unkown
page read and write
clean
179000
unkown
page read and write
clean
1DA000
heap private
page read and write
clean
30EE000
stack
page read and write
clean
442000
unkown
page read and write
clean
3F37000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
25D0000
heap private
page read and write
clean
3E60000
heap private
page read and write
clean
2370000
unkown
page read and write
clean
22E0000
unkown
page read and write
clean
1F0000
unkown
page read and write
clean
2E73000
unkown
page read and write
clean
420000
heap default
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
23E5000
heap private
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
3F4F000
unkown
page read and write
clean
3700000
unkown image
page readonly
clean
1E0000
unkown image
page read and write
clean
5E4000
heap private
page read and write
clean
18D000
unkown
page read and write
clean
3FF0000
heap private
page read and write
clean
2DB0000
heap private
page read and write
clean
3F9000
unkown
page read and write
clean
20000
unkown image
page read and write
clean
2860000
unkown
page read and write
clean
4E6000
heap default
page read and write
clean
2328000
unkown
page read and write
clean
427000
heap default
page read and write
clean
3F14000
unkown
page read and write
clean
22DC000
unkown
page read and write
clean
160000
unkown
page read and write
clean
22FC000
unkown
page read and write
clean
409000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
3C50000
heap private
page read and write
clean
BF0000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
408000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
5DA2000
unkown image
page readonly
clean
2E72000
unkown
page read and write
clean
42A000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
3FA000
unkown
page read and write
clean
452000
unkown
page read and write
clean
2DAB000
heap private
page read and write
clean
23E0000
heap private
page read and write
clean
BE0000
unkown image
page readonly
clean
132000
unkown
page read and write
clean
162000
unkown
page read and write
clean
3320000
unkown image
page readonly
clean
15E000
unkown
page read and write
clean
42A000
unkown
page read and write
clean
2095000
heap private
page read and write
clean
2C50000
unkown
page read and write
clean
2D70000
heap private
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
2309000
unkown
page read and write
clean
53F000
stack
page read and write
clean
3F00000
unkown
page read and write
clean
1D0000
heap private
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
2C7F000
stack
page read and write
clean
2F6000
unkown
page read and write
clean
2E75000
unkown
page read and write
clean
2304000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
42A000
unkown
page read and write
clean
3F21000
unkown
page read and write
clean
3F0000
unkown
page read and write
clean
2460000
unkown image
page readonly
clean
45E000
heap default
page read and write
clean
2320000
unkown
page read and write
clean
2DB5000
heap private
page read and write
clean
20F4000
heap private
page read and write
clean
A60000
unkown image
page readonly
clean
1D4000
heap private
page read and write
clean
22E4000
unkown
page read and write
clean
22D4000
unkown
page read and write
clean
20CB000
heap private
page read and write
clean
3507000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
2E7C000
unkown
page read and write
clean
2CD000
heap default
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
2AAF000
stack
page read and write
clean
3F25000
unkown
page read and write
clean
1DD000
heap private
page read and write
clean
4C9000
heap default
page read and write
clean
3FB000
unkown
page read and write
clean
4C3000
heap default
page read and write
clean
2DB000
heap default
page read and write
clean
2180000
unkown image
page readonly
clean
22D8000
unkown
page read and write
clean
B6F000
stack
page read and write
clean
2E77000
unkown
page read and write
clean
3F12000
unkown
page read and write
clean
2D60000
heap private
page read and write
clean
10000
unkown image
page read and write
clean
20FB000
heap private
page read and write
clean
2364000
unkown
page read and write
clean
22E8000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
23B0000
unkown image
page readonly
clean
4400000
unkown
page read and write
clean
42A000
unkown
page read and write
clean
260000
heap private
page read and write
clean
50B000
heap default
page read and write
clean
3F08000
unkown
page read and write
clean
23C0000
unkown image
page readonly
clean
5BF000
stack
page read and write
clean
444000
unkown
page read and write
clean
179000
unkown
page read and write
clean
15E000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
27A000
unkown
page read and write
clean
297000
heap default
page read and write
clean
22F8000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
2358000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
20D6000
heap private
page read and write
clean
2B6F000
stack
page read and write
clean
234C000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
2300000
unkown
page read and write
clean
42F000
unkown
page read and write
clean
2DF0000
heap private
page read and write
clean
3A0000
heap default
page read and write
clean
10000
unkown image
page read and write
clean
179000
unkown
page read and write
clean
22BC000
unkown
page read and write
clean
77F000
stack
page read and write
clean
2360000
unkown
page read and write
clean
454000
unkown
page read and write
clean
436F000
stack
page read and write
clean
2354000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
2E7B000
unkown
page read and write
clean
2190000
unkown image
page read and write
clean
2319000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
3F2A000
unkown
page read and write
clean
408000
unkown
page read and write
clean
136000
unkown
page read and write
clean
3F23000
unkown
page read and write
clean
12D000
unkown
page read and write
clean
232C000
unkown
page read and write
clean
42A000
unkown
page read and write
clean
498F000
stack
page read and write
clean
5F0000
unkown image
page readonly
clean
2234000
heap private
page read and write
clean
2350000
unkown
page read and write
clean
176000
unkown
page read and write
clean
3EE0000
unkown
page read and write
clean
21B0000
unkown
page read and write
clean
3D10000
heap private
page read and write
clean
390000
unkown
page read and write
clean
22F4000
unkown
page read and write
clean
13F000
unkown
page read and write
clean
3F8000
unkown
page read and write
clean
179000
unkown
page read and write
clean
D0000
unkown
page read and write
clean
42F000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
1D10000
unkown image
page readonly
clean
3F27000
unkown
page read and write
clean
D0000
unkown
page read and write
clean
770000
unkown image
page readonly
clean
22C0000
unkown
page read and write
clean
4180000
heap private
page read and write
clean
122000
unkown
page read and write
clean
3F1F000
unkown
page read and write
clean
2C86000
unkown
page read and write
clean
28C0000
unkown image
page readonly
clean
143000
unkown
page read and write
clean
20F0000
heap private
page read and write
clean
2E70000
unkown
page read and write
clean
5E0000
heap private
page read and write
clean
290000
heap default
page read and write
clean
3F3F000
unkown
page read and write
clean
241B000
heap private
page read and write
clean
3EB000
unkown
page read and write
clean
2BD0000
heap private
page read and write
clean
22D0000
unkown
page read and write
clean
22B8000
unkown
page read and write
clean
15E000
unkown
page read and write
clean
5C0000
unkown image
page read and write
clean
2E78000
unkown
page read and write
clean
2090000
heap private
page read and write
clean
2330000
unkown
page read and write
clean
2BAF000
stack
page read and write
clean
408000
unkown
page read and write
clean
22CC000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
2D8D000
stack
page read and write
clean
233C000
unkown
page read and write
clean
C5E000
stack
page read and write
clean
2E79000
unkown
page read and write
clean
119000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
3F18000
unkown
page read and write
clean
2820000
unkown
page read and write
clean
106000
unkown
page read and write
clean
2E71000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
21C0000
heap private
page read and write
clean
2D6000
heap default
page read and write
clean
125000
unkown
page read and write
clean
2D75000
heap private
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
2840000
heap private
page read and write
clean
3F31000
unkown
page read and write
clean
20DF000
heap private
page read and write
clean
40000
unkown image
page readonly
clean
2E7A000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
1D0000
unkown image
page readonly
clean
D80000
unkown image
page readonly
clean
42F000
unkown
page read and write
clean
2230000
heap private
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
780000
unkown image
page readonly
clean
106000
unkown
page read and write
clean
59B2000
unkown image
page read and write
clean
53F000
stack
page read and write
clean
219E000
stack
page read and write
clean
2F3F000
stack
page read and write
clean
2D65000
heap private
page read and write
clean
2338000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
3C6000
unkown
page read and write
clean
42A000
unkown
page read and write
clean
2740000
heap private
page read and write
clean
40000
unkown image
page readonly
clean
4A0000
unkown
page read and write
clean
22F0000
unkown
page read and write
clean
3DE000
heap default
page read and write
clean
7EFE0000
unkown image
page readonly
clean
3B80000
heap private
page read and write
clean
3A7000
heap default
page read and write
clean
4380000
heap private
page read and write
clean
26C0000
heap private
page read and write
clean
3F3A000
unkown
page read and write
clean
3F0F000
unkown
page read and write
clean
2E76000
unkown
page read and write
clean
2374000
unkown
page read and write
clean
2A40000
heap private
page read and write
clean
3F16000
unkown
page read and write
clean
15C000
unkown
page read and write
clean
13D000
unkown
page read and write
clean
22C8000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
2E74000
unkown
page read and write
clean
There are 256 hidden memdumps, click here to show them.