IOC Report

loading gif

Files

File Path
Type
Category
Malicious
survey-1384723731.xls
Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1251, Name of Creating Application: Microsoft Excel, Create Time/Date: Fri Jun 5 19:19:34 2015, Last Saved Time/Date: Thu Nov 25 10:07:14 2021, Security: 0
initial sample
malicious
C:\Users\user\Desktop\survey-1384723731.xls
Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1251, Name of Creating Application: Microsoft Excel, Create Time/Date: Fri Jun 5 19:19:34 2015, Last Saved Time/Date: Thu Nov 25 10:07:14 2021, Security: 0
dropped
malicious
C:\Users\user\AppData\Local\Temp\91C4.tmp
Composite Document File V2 Document, Cannot read section info
dropped
clean
C:\Users\user\AppData\Local\Temp\~DF22AC4F44EF579D15.TMP
data
dropped
clean
C:\Users\user\AppData\Local\Temp\~DF8E36D078DBA15E72.TMP
data
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
"C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /automation -Embedding
malicious
C:\Windows\System32\regsvr32.exe
"C:\Windows\System32\regsvr32.exe" C:\Datop\besta.ocx
malicious
C:\Windows\System32\regsvr32.exe
"C:\Windows\System32\regsvr32.exe" C:\Datop\bestb.ocx
malicious
C:\Windows\System32\regsvr32.exe
"C:\Windows\System32\regsvr32.exe" C:\Datop\bestc.ocx
malicious

URLs

Name
IP
Malicious
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
unknown
clean
http://www.windows.com/pctv.
unknown
clean
http://investor.msn.com
unknown
clean
http://www.msnbc.com/news/ticker.txt
unknown
clean
http://www.icra.org/vocabulary/.
unknown
clean
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
unknown
clean
http://investor.msn.com/
unknown
clean
https://klevvrtech.com/zxywJAC24KJ/ji.html
192.185.79.2
clean
http://www.%s.comPA
unknown
clean
https://srkcampus.org/OYcMRJbL/ji.html
192.185.129.7
clean
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
unknown
clean
http://www.hotmail.com/oe
unknown
clean
http://servername/isapibackend.dll
unknown
clean
https://rstebet.co.id/fbmKk6n48G/ji.html
103.247.11.218
clean
There are 4 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
klevvrtech.com
192.185.79.2
clean
rstebet.co.id
103.247.11.218
clean
srkcampus.org
192.185.129.7
clean

IPs

IP
Domain
Country
Malicious
192.185.129.7
srkcampus.org
United States
clean
192.185.79.2
klevvrtech.com
United States
clean
103.247.11.218
rstebet.co.id
Indonesia
clean

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
-x*
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel
MTTT
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\2EB58
2EB58
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
VBAFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
6*+
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\MuiCache\151\52C64B7E
@%SystemRoot%\system32\qagentrt.dll,-10
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\MuiCache\151\52C64B7E
@%SystemRoot%\System32\fveui.dll,-843
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\MuiCache\151\52C64B7E
@%SystemRoot%\System32\fveui.dll,-844
clean
HKEY_CURRENT_USER_CLASSES\Local Settings\MuiCache\151\52C64B7E
@%SystemRoot%\System32\wuaueng.dll,-400
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
ProductNonBootFilesIntl_1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Place MRU
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 1
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 2
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 3
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 4
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 5
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 6
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 7
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 8
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 9
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 10
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 11
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 12
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 13
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 14
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 15
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 16
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 17
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 18
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 19
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 20
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\39B55
39B55
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Place MRU
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Max Display
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 1
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 2
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 3
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 4
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 5
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 6
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 7
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 8
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 9
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 10
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 11
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 12
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 13
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 14
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 15
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 16
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 17
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 18
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 19
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 20
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\3A2C4
3A2C4
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Security\Trusted Documents
LastPurgeTime
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
EXCELFiles
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
clean
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\12891DF7B048CD69D0196C8AD7A754C8A812A08C
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\12891DF7B048CD69D0196C8AD7A754C8A812A08C
Blob
clean
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60090400100000000F01FEC\Usage
ProductNonBootFilesIntl_1033
clean
There are 61 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
2C6000
unkown
page read and write
clean
3F55000
heap private
page read and write
clean
2A0000
unkown image
page readonly
clean
180000
unkown
page read and write
clean
1E0000
heap private
page read and write
clean
25E000
heap default
page read and write
clean
2130000
unkown image
page readonly
clean
560000
unkown image
page readonly
clean
554000
heap private
page read and write
clean
207000
heap default
page read and write
clean
336000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
365000
unkown
page read and write
clean
2E7000
heap default
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
2AC000
unkown
page read and write
clean
2B5000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
2C4000
unkown
page read and write
clean
20B5000
heap private
page read and write
clean
219B000
heap private
page read and write
clean
4A47000
unkown image
page readonly
clean
400000
unkown
page read and write
clean
510000
heap private
page read and write
clean
285000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
3EB5000
heap private
page read and write
clean
159000
unkown
page read and write
clean
20000
unkown image
page readonly
clean
1A0000
unkown image
page readonly
clean
2A4000
unkown
page read and write
clean
375000
unkown
page read and write
clean
1C0000
unkown
page read and write
clean
2E0000
heap default
page read and write
clean
790000
unkown image
page readonly
clean
3F50000
heap private
page read and write
clean
4900000
unkown image
page readonly
clean
220000
heap default
page read and write
clean
26E000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
54B000
heap private
page read and write
clean
4F4000
heap private
page read and write
clean
170000
heap private
page read and write
clean
436000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
384000
unkown
page read and write
clean
1B0000
unkown image
page readonly
clean
30000
unkown image
page readonly
clean
2C5000
unkown
page read and write
clean
2F0000
unkown
page read and write
clean
3D5000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
22CE000
stack
page read and write
clean
4AE7000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
2A4000
unkown
page read and write
clean
295000
unkown
page read and write
clean
33A000
heap default
page read and write
clean
2B0000
heap private
page read and write
clean
4D7F000
stack
page read and write
clean
30000
unkown image
page readonly
clean
2000000
unkown image
page readonly
clean
160000
unkown image
page read and write
clean
320000
unkown
page read and write
clean
273000
heap default
page read and write
clean
2EF000
unkown
page read and write
clean
6E0000
unkown image
page readonly
clean
515000
heap private
page read and write
clean
10000
unkown image
page read and write
clean
1A0000
unkown
page execute and read and write
clean
27A000
heap default
page read and write
clean
180000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
5E0000
unkown image
page readonly
clean
22B0000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
200000
heap default
page read and write
clean
28A000
unkown
page read and write
clean
2A5000
unkown
page read and write
clean
285000
unkown
page read and write
clean
384000
unkown
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
190000
unkown
page execute and read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
3EF5000
heap private
page read and write
clean
416000
unkown
page read and write
clean
2165000
heap private
page read and write
clean
28A000
unkown
page read and write
clean
3EF9000
heap private
page read and write
clean
7EFE0000
unkown image
page readonly
clean
7FFFFFB2000
unkown image
page readonly
clean
356000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
290000
unkown
page execute and read and write
clean
500000
unkown
page read and write
clean
174000
heap private
page read and write
clean
310000
unkown
page read and write
clean
20000
unkown image
page readonly
clean
386000
unkown
page read and write
clean
4CFF000
stack
page read and write
clean
384000
unkown
page read and write
clean
1F80000
unkown image
page readonly
clean
536000
unkown
page read and write
clean
39E0000
unkown image
page readonly
clean
550000
heap private
page read and write
clean
20000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
30F000
unkown
page read and write
clean
2350000
unkown
page read and write
clean
1E4000
heap private
page read and write
clean
20EB000
heap private
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
6F0000
unkown image
page readonly
clean
10000
unkown image
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
40000
unkown image
page readonly
clean
315000
unkown
page read and write
clean
2A4000
unkown
page read and write
clean
385000
unkown
page read and write
clean
5D0000
heap private
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
170000
unkown
page read and write
clean
2360000
unkown
page read and write
clean
4A87000
unkown image
page readonly
clean
20B0000
heap private
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
7FFFFFD0000
unkown image
page readonly
clean
2AA000
unkown
page read and write
clean
2C4000
unkown
page read and write
clean
7FFFFFD0000
unkown image
page readonly
clean
48A0000
unkown image
page readonly
clean
2B5000
unkown
page read and write
clean
760000
unkown image
page readonly
clean
282000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
333000
heap default
page read and write
clean
3A90000
unkown image
page readonly
clean
1B6000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
2F5000
unkown
page read and write
clean
31E000
heap default
page read and write
clean
C9000
unkown
page read and write
clean
160000
unkown image
page read and write
clean
2A6000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
2A2000
unkown
page read and write
clean
375000
unkown
page read and write
clean
227000
heap default
page read and write
clean
3F59000
heap private
page read and write
clean
1D20000
unkown image
page readonly
clean
3CF000
unkown
page read and write
clean
2B4000
heap private
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
28E000
unkown
page read and write
clean
34A000
unkown
page read and write
clean
600000
unkown image
page readonly
clean
23E000
heap default
page read and write
clean
3EB9000
heap private
page read and write
clean
34E000
unkown
page read and write
clean
4F0000
heap private
page read and write
clean
7FFFFFB0000
unkown image
page readonly
clean
7FFFFFC0000
unkown image
page readonly
clean
590000
unkown
page read and write
clean
2A5000
unkown
page read and write
clean
2C4000
unkown
page read and write
clean
7FFFFFC2000
unkown image
page readonly
clean
253000
heap default
page read and write
clean
2A5000
unkown
page read and write
clean
2160000
heap private
page read and write
clean
365000
unkown
page read and write
clean
7FFFFFB2000
unkown image
page readonly
clean
E9000
unkown
page read and write
clean
4E0000
unkown
page read and write
clean
25A000
heap default
page read and write
clean
1D00000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
26A000
unkown
page read and write
clean
7FFFFFC0000
unkown image
page readonly
clean
770000
unkown image
page readonly
clean
295000
unkown
page read and write
clean
300000
unkown
page read and write
clean
30000
unkown image
page readonly
clean
7FFFFFB0000
unkown image
page readonly
clean
362000
unkown
page read and write
clean
7EFE0000
unkown image
page readonly
clean
3D0000
unkown
page read and write
clean
3EF0000
heap private
page read and write
clean
36C000
unkown
page read and write
clean
3A80000
unkown image
page readonly
clean
5D4000
heap private
page read and write
clean
28C000
unkown
page read and write
clean
3EB0000
heap private
page read and write
clean
160000
unkown image
page read and write
clean
780000
unkown image
page readonly
clean
3E0000
unkown
page read and write
clean
170000
unkown
page read and write
clean
36A000
unkown
page read and write
clean
4860000
unkown image
page readonly
clean
1C80000
unkown image
page readonly
clean
There are 191 hidden memdumps, click here to show them.