IOC Report

loading gif

Files

File Path
Type
Category
Malicious
Netflix coupon-32822.xlsb
Microsoft Excel 2007+
initial sample
malicious
C:\ProgramData\QiLuJMFtkBaWg.rtf
HTML document, ASCII text, with very long lines, with CRLF line terminators
dropped
malicious
C:\Users\user\Desktop\~$Netflix coupon-32822.xlsb
data
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\781FED27.png
PNG image data, 225 x 318, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\9F568E3E.png
PNG image data, 293 x 40, 8-bit/color RGB, non-interlaced
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
"C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /automation -Embedding
malicious
C:\Windows\System32\wbem\WMIC.exe
wmic process call create "mshta C:\ProgramData\QiLuJMFtkBaWg.rtf"
malicious
C:\Windows\System32\mshta.exe
mshta C:\ProgramData\QiLuJMFtkBaWg.rtf
clean

URLs

Name
IP
Malicious
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
unknown
clean
http://www.windows.com/pctv.
unknown
clean
http://investor.msn.com
unknown
clean
http://www.msnbc.com/news/ticker.txt
unknown
clean
http://www.%s.comPA
unknown
clean
http://www.icra.org/vocabulary/.
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
unknown
clean
http://www.hotmail.com/oe
unknown
clean
http://servername/isapibackend.dll
unknown
clean
http://investor.msn.com/
unknown
clean
There are 1 hidden URLs, click here to show them.

IPs

IP
Domain
Country
Malicious
158.140.185.205
unknown
Indonesia
clean

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
4r-
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel
MTTT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\2D114
2D114
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
VBAFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
6y-
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
ProductNonBootFilesIntl_1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Security\Trusted Documents
LastPurgeTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
EXCELFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
ProductNonBootFilesIntl_1033
clean
There are 4 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
302B000
unkown
page read and write
clean
3027000
unkown
page read and write
clean
219000
unkown
page read and write
clean
1C6000
unkown
page read and write
clean
3E8000
unkown
page read and write
clean
1E0000
heap default
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
26CC000
unkown
page read and write
clean
21C6000
heap private
page read and write
clean
2608000
unkown
page read and write
clean
3024000
unkown
page read and write
clean
4B80000
unkown
page read and write
clean
1BA0000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
7FFFFFC2000
unkown image
page readonly
clean
239000
unkown
page read and write
clean
21D000
heap default
page read and write
clean
3E60000
unkown image
page readonly
clean
3D9000
unkown
page read and write
clean
C9F000
stack
page read and write
clean
20000
unkown image
page read and write
clean
4BD0000
unkown
page read and write
clean
226000
heap default
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
40A000
unkown
page read and write
clean
18A000
unkown
page read and write
clean
2640000
unkown
page read and write
clean
240000
unkown
page read and write
clean
3DB000
unkown
page read and write
clean
36AF000
stack
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
2E0000
unkown
page read and write
clean
3021000
unkown
page read and write
clean
5F4000
heap private
page read and write
clean
240000
unkown
page read and write
clean
2634000
unkown
page read and write
clean
4BA3000
unkown
page read and write
clean
387000
heap default
page read and write
clean
222000
unkown
page read and write
clean
286F000
stack
page read and write
clean
2610000
unkown
page read and write
clean