IOC Report

loading gif

Files

File Path
Type
Category
Malicious
Netflix coupon-32822.xlsb
Microsoft Excel 2007+
initial sample
malicious
C:\ProgramData\QiLuJMFtkBaWg.rtf
HTML document, ASCII text, with very long lines, with CRLF line terminators
dropped
malicious
C:\Users\user\Desktop\~$Netflix coupon-32822.xlsb
data
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\781FED27.png
PNG image data, 225 x 318, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\9F568E3E.png
PNG image data, 293 x 40, 8-bit/color RGB, non-interlaced
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
"C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /automation -Embedding
malicious
C:\Windows\System32\wbem\WMIC.exe
wmic process call create "mshta C:\ProgramData\QiLuJMFtkBaWg.rtf"
malicious
C:\Windows\System32\mshta.exe
mshta C:\ProgramData\QiLuJMFtkBaWg.rtf
clean

URLs

Name
IP
Malicious
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
unknown
clean
http://www.windows.com/pctv.
unknown
clean
http://investor.msn.com
unknown
clean
http://www.msnbc.com/news/ticker.txt
unknown
clean
http://www.%s.comPA
unknown
clean
http://www.icra.org/vocabulary/.
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
unknown
clean
http://www.hotmail.com/oe
unknown
clean
http://servername/isapibackend.dll
unknown
clean
http://investor.msn.com/
unknown
clean
There are 1 hidden URLs, click here to show them.

IPs

IP
Domain
Country
Malicious
158.140.185.205
unknown
Indonesia
clean

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
4r-
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel
MTTT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\2D114
2D114
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
VBAFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
6y-
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
ProductNonBootFilesIntl_1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Security\Trusted Documents
LastPurgeTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
EXCELFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
ProductNonBootFilesIntl_1033
clean
There are 4 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
302B000
unkown
page read and write
clean
3027000
unkown
page read and write
clean
219000
unkown
page read and write
clean
1C6000
unkown
page read and write
clean
3E8000
unkown
page read and write
clean
1E0000
heap default
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
26CC000
unkown
page read and write
clean
21C6000
heap private
page read and write
clean
2608000
unkown
page read and write
clean
3024000
unkown
page read and write
clean
4B80000
unkown
page read and write
clean
1BA0000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
239000
unkown
page read and write
clean
21D000
heap default
page read and write
clean
3E60000
unkown image
page readonly
clean
3D9000
unkown
page read and write
clean
C9F000
stack
page read and write
clean
20000
unkown image
page read and write
clean
4BD0000
unkown
page read and write
clean
226000
heap default
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
40A000
unkown
page read and write
clean
18A000
unkown
page read and write
clean
2640000
unkown
page read and write
clean
240000
unkown
page read and write
clean
3DB000
unkown
page read and write
clean
36AF000
stack
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
2E0000
unkown
page read and write
clean
3021000
unkown
page read and write
clean
5F4000
heap private
page read and write
clean
240000
unkown
page read and write
clean
2634000
unkown
page read and write
clean
4BA3000
unkown
page read and write
clean
387000
heap default
page read and write
clean
222000
unkown
page read and write
clean
286F000
stack
page read and write
clean
2610000
unkown
page read and write
clean
10000
unkown image
page read and write
clean
307000
heap default
page read and write
clean
610000
unkown image
page readonly
clean
7EFE0000
unkown image
page readonly
clean
21EB000
heap private
page read and write
clean
4BB9000
unkown
page read and write
clean
2CE5000
heap private
page read and write
clean
4BA5000
unkown
page read and write
clean
272000
unkown
page read and write
clean
2644000
unkown
page read and write
clean
2640000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
28A0000
unkown image
page readonly
clean
3DA000
unkown
page read and write
clean
40F000
unkown
page read and write
clean
228000
heap default
page read and write
clean
234000
unkown
page read and write
clean
2185000
heap private
page read and write
clean
1E7000
heap default
page read and write
clean
258000
unkown
page read and write
clean
22B000
unkown
page read and write
clean
3D0000
unkown
page read and write
clean
53D0000
heap private
page read and write
clean
2FA0000
heap private
page read and write
clean
32D0000
heap private
page read and write
clean
23B000
unkown
page read and write
clean
9DF000
stack
page read and write
clean
2B50000
heap private
page read and write
clean
2A2F000
stack
page read and write
clean
2669000
unkown
page read and write
clean
40D000
unkown
page read and write
clean
26B4000
unkown
page read and write
clean
27B0000
unkown image
page readonly
clean
34A0000
heap private
page read and write
clean
F0000
unkown
page read and write
clean
350000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
2900000
heap private
page read and write
clean
3CB000
unkown
page read and write
clean
BEF000
stack
page read and write
clean
3026000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
3025000
unkown
page read and write
clean
42B000
unkown
page read and write
clean
26C0000
unkown
page read and write
clean
2659000
unkown
page read and write
clean
E0000
unkown image
page read and write
clean
370000
heap private
page read and write
clean
302C000
unkown
page read and write
clean
40A000
unkown
page read and write
clean
25C0000
heap private
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
2734000
heap private
page read and write
clean
432000
unkown
page read and write
clean
26C8000
unkown
page read and write
clean
3FF000
heap default
page read and write
clean
3020000
unkown
page read and write
clean
3E8000
unkown
page read and write
clean
348F000
stack
page read and write
clean
21E4000
heap private
page read and write
clean
2E40000
unkown
page read and write
clean
26A0000
unkown
page read and write
clean
2654000
unkown
page read and write
clean
272000
unkown
page read and write
clean
26B0000
unkown
page read and write
clean
269C000
unkown
page read and write
clean
277000
unkown
page read and write
clean
2670000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
4BB7000
unkown
page read and write
clean
24D0000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
267C000
unkown
page read and write
clean
25C000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
268C000
unkown
page read and write
clean
3022000
unkown
page read and write
clean
2618000
unkown
page read and write
clean
28B0000
unkown image
page readonly
clean
5230000
heap private
page read and write
clean
32D5000
heap private
page read and write
clean
32D9000
heap private
page read and write
clean
2688000
unkown
page read and write
clean
53AF000
stack
page read and write
clean
4B94000
unkown
page read and write
clean
5F0000
heap private
page read and write
clean
2624000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
25C000
unkown
page read and write
clean
2628000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
4CE0000
heap private
page read and write
clean
4BA1000
unkown
page read and write
clean
302A000
unkown
page read and write
clean
2740000
heap private
page read and write
clean
2CE0000
heap private
page read and write
clean
423000
unkown
page read and write
clean
3BE000
heap default
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
4B9E000
unkown
page read and write
clean
40F000
unkown
page read and write
clean
2630000
unkown
page read and write
clean
21CF000
heap private
page read and write
clean
40000
unkown image
page readonly
clean
35C0000
heap private
page read and write
clean
4BB1000
unkown
page read and write
clean
316000
unkown
page read and write
clean
33E000
heap default
page read and write
clean
5450000
unkown
page read and write
clean
22E000
unkown
page read and write
clean
264C000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
260C000
unkown
page read and write
clean
E70000
unkown image
page readonly
clean
2650000
unkown
page read and write
clean
4B8F000
unkown
page read and write
clean
4B97000
unkown
page read and write
clean
2C0000
heap private
page read and write
clean
D0000
unkown image
page readonly
clean
40D000
unkown
page read and write
clean
3A80000
unkown image
page readonly
clean
2680000
unkown
page read and write
clean
4BBE000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
28E0000
unkown
page read and write
clean
2638000
unkown
page read and write
clean
50A0000
heap private
page read and write
clean
1D0000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
2E3F000
stack
page read and write
clean
40F000
unkown
page read and write
clean
300000
heap default
page read and write
clean
26A8000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
4BAA000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
1FCE000
stack
page read and write
clean
422000
unkown
page read and write
clean
21BB000
heap private
page read and write
clean
2D0F000
stack
page read and write
clean
2678000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
1F3F000
stack
page read and write
clean
40000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
380000
heap default
page read and write
clean
3E8000
unkown
page read and write
clean
4B86000
unkown
page read and write
clean
2730000
heap private
page read and write
clean
6C62000
unkown image
page readonly
clean
2950000
heap private
page read and write
clean
3D8000
unkown
page read and write
clean
2590000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
2648000
unkown
page read and write
clean
275000
unkown
page read and write
clean
3023000
unkown
page read and write
clean
17D000
unkown
page read and write
clean
262C000
unkown
page read and write
clean
298B000
heap private
page read and write
clean
30B5000
heap private
page read and write
clean
10000
unkown image
page read and write
clean
3A1000
heap default
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
42B000
unkown
page read and write
clean
261C000
unkown
page read and write
clean
206000
unkown
page read and write
clean
42B000
unkown
page read and write
clean
6872000
unkown image
page read and write
clean
30AF000
stack
page read and write
clean
4EB0000
heap private
page read and write
clean
4B0000
heap private
page read and write
clean
26A4000
unkown
page read and write
clean
21E0000
heap private
page read and write
clean
326D000
stack
page read and write
clean
434000
unkown
page read and write
clean
3C67000
unkown image
page readonly
clean
1FE0000
heap private
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
FF0000
unkown image
page readonly
clean
3C2000
heap default
page read and write
clean
35C5000
heap private
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
3E7000
heap default
page read and write
clean
1190000
unkown image
page readonly
clean
5FA000
heap private
page read and write
clean
1C6000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
30B0000
heap private
page read and write
clean
3029000
unkown
page read and write
clean
1EB0000
unkown image
page read and write
clean
2676000
unkown
page read and write
clean
1000000
unkown image
page readonly
clean
4BA7000
unkown
page read and write
clean
480000
unkown image
page readonly
clean
40D000
unkown
page read and write
clean
5FD000
heap private
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
2620000
unkown
page read and write
clean
25C0000
unkown
page read and write
clean
35FB000
heap private
page read and write
clean
4B4000
heap private
page read and write
clean
7EFE0000
unkown image
page readonly
clean
3028000
unkown
page read and write
clean
232000
unkown
page read and write
clean
2180000
heap private
page read and write
clean
190000
unkown
page read and write
clean
25A0000
unkown image
page read and write
clean
600000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
3E8000
unkown
page read and write
clean
2D90000
heap private
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
2955000
heap private
page read and write
clean
7EFE0000
unkown image
page readonly
clean
40A000
unkown
page read and write
clean
38BE000
stack
page read and write
clean
374000
heap private
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
There are 254 hidden memdumps, click here to show them.