IOC Report
20220714 DWG.doc

loading gif

Files

File Path
Type
Category
Malicious
20220714 DWG.doc
Zip archive data, at least v2.0 to extract
initial sample
malicious
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\20220714 DWG.doc.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Tue Mar 8 15:31:53 2022, mtime=Fri Jul 15 21:26:43 2022, atime=Fri Jul 15 21:26:30 2022, length=952586, window=hide
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Office\16.0\OfficeFileCache\CentralTable.accdb
Microsoft Access Database
dropped
C:\Users\user\AppData\Local\Microsoft\Office\16.0\OfficeFileCache\CentralTable.ini
data
dropped
C:\Users\user\AppData\Local\Microsoft\Office\16.0\OfficeFileCache\CentralTable.laccdb
data
dropped
C:\Users\user\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\FB6DECAC-D518-44FC-A2B0-E6C0B9BDC76F
XML 1.0 document, UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\678899CC.htm
HTML document, ASCII text, with very long lines, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\E503F16F.png
PNG image data, 2317 x 3433, 8-bit colormap, non-interlaced
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\FF013E73.htm
HTML document, ASCII text, with very long lines, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.Word\~WRS{3F734575-446A-409F-ABF0-279D9EE55D72}.tmp
data
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.Word\~WRS{D2D7FF17-FD00-4D6F-9BD0-D27E7B55D2C5}.tmp
data
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\Glomet[1].htm
HTML document, ASCII text, with very long lines, with CRLF line terminators
downloaded
C:\Users\user\AppData\Local\Temp\RES216A.tmp
Intel 80386 COFF object file, not stripped, 3 sections, symbol offset=0x4ae, 9 symbols
dropped
C:\Users\user\AppData\Local\Temp\RES3EE5.tmp
Intel 80386 COFF object file, not stripped, 3 sections, symbol offset=0x4ae, 9 symbols
dropped
C:\Users\user\AppData\Local\Temp\RESDEDE.tmp
Intel 80386 COFF object file, not stripped, 3 sections, symbol offset=0x4ae, 9 symbols
dropped
C:\Users\user\AppData\Local\Temp\ea13q231\CSCF24C6B632D84EA4B9FDE29780CB1444.TMP
MSVC .res
dropped
C:\Users\user\AppData\Local\Temp\ea13q231\ea13q231.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\llhoph4d\CSCA6DEB1F21B847AF87589FE9AEBF81D1.TMP
MSVC .res
dropped
C:\Users\user\AppData\Local\Temp\llhoph4d\llhoph4d.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\nsb11EA.tmp\nsExec.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\q0vyiohn\CSC14339BC3D3E94BA0AEA5453DEFD3E9E.TMP
MSVC .res
dropped
C:\Users\user\AppData\Local\Temp\q0vyiohn\q0vyiohn.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Roaming\Microsoft\Templates\~$Normal.dotm
data
dropped
C:\Users\user\Desktop\~$220714 DWG.doc
data
dropped
C:\Users\user\Pictures\Cellekammeraten\PRVEBALLONS\Omstigningens\Adventure_7.bmp
JPEG image data, JFIF standard 1.01, resolution (DPI), density 100x100, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=3], baseline, precision 8, 110x110, frames 3
dropped
C:\Users\user\Pictures\Cellekammeraten\PRVEBALLONS\Omstigningens\BLINDERS.PAR
data
dropped
C:\Users\user\Pictures\Cellekammeraten\PRVEBALLONS\Omstigningens\Fns\differentieringerne\PHOTOCOMPOSE\serpigoes\api-ms-win-core-timezone-l1-1-0.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
C:\Users\user\Pictures\Cellekammeraten\PRVEBALLONS\Omstigningens\GENOPBYGGEDE\Intraretinal\Tilstningsfries\api-ms-win-crt-stdio-l1-1-0.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
C:\Users\user\Pictures\Cellekammeraten\PRVEBALLONS\Omstigningens\GENOPBYGGEDE\Intraretinal\Tilstningsfries\application-x-firmware-symbolic.symbolic.png
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
dropped
C:\Users\user\Pictures\Cellekammeraten\PRVEBALLONS\Omstigningens\GENOPBYGGEDE\Intraretinal\Tilstningsfries\battery-level-90-charging-symbolic.svg
SVG Scalable Vector Graphics image
dropped
C:\Users\user\Pictures\Cellekammeraten\PRVEBALLONS\Omstigningens\Lektionskatalogets1\network-vpn-acquiring-symbolic.symbolic.png
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
dropped
C:\Users\user\Pictures\Cellekammeraten\PRVEBALLONS\Omstigningens\REDO\DYSMENORRHEIC\Tidehead7\Kartonens\Green_Leaves_9.bmp
JPEG image data, JFIF standard 1.01, resolution (DPI), density 100x100, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=3], baseline, precision 8, 110x110, frames 3
dropped
C:\Users\user\Pictures\Cellekammeraten\PRVEBALLONS\Omstigningens\REDO\DYSMENORRHEIC\Tidehead7\Kartonens\MsMpRes.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\Pictures\Cellekammeraten\PRVEBALLONS\Omstigningens\Redbones\document-revert-symbolic.svg
SVG Scalable Vector Graphics image
dropped
C:\Users\user\Pictures\Cellekammeraten\PRVEBALLONS\Omstigningens\Redbones\folder-remote-symbolic.svg
SVG Scalable Vector Graphics image
dropped
C:\Users\user\Pictures\Cellekammeraten\PRVEBALLONS\Omstigningens\Redbones\folder-remote.png
PNG image data, 16 x 16, 8-bit colormap, non-interlaced
dropped
C:\Users\user\Pictures\Cellekammeraten\PRVEBALLONS\Omstigningens\Redbones\format-text-direction-symbolic-rtl.svg
SVG Scalable Vector Graphics image
dropped
C:\Users\user\Pictures\Cellekammeraten\PRVEBALLONS\Omstigningens\Redbones\go-next-symbolic-rtl.svg
SVG Scalable Vector Graphics image
dropped
C:\Users\user\Pictures\Cellekammeraten\PRVEBALLONS\Omstigningens\Redbones\input-gaming-symbolic.svg
SVG Scalable Vector Graphics image
dropped
C:\Users\user\Pictures\Cellekammeraten\PRVEBALLONS\Omstigningens\Redbones\libmpdec-2.dll
PE32+ executable (DLL) (console) x86-64 (stripped to external PDB), for MS Windows
dropped
C:\Users\user\Pictures\Cellekammeraten\PRVEBALLONS\Omstigningens\Redbones\network-cellular-4g-symbolic.svg
SVG Scalable Vector Graphics image
dropped
C:\Users\user\Pictures\Cellekammeraten\PRVEBALLONS\Omstigningens\Redbones\network-server.png
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
dropped
C:\Users\user\Pictures\Cellekammeraten\PRVEBALLONS\Omstigningens\Strawberries\MOLAKKORD\SetEHCIKey.exe
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
C:\Users\user\Pictures\Cellekammeraten\PRVEBALLONS\Omstigningens\immittance\tittes\RETSLRDE.Dia
ASCII text, with very long lines, with no line terminators
dropped
C:\Windows\Temp\SDIAG_26d32acb-2999-4d66-b897-077572d4c005\DiagPackage.diagpkg
HTML document, ASCII text, with CRLF line terminators
dropped
C:\Windows\Temp\SDIAG_26d32acb-2999-4d66-b897-077572d4c005\DiagPackage.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Windows\Temp\SDIAG_26d32acb-2999-4d66-b897-077572d4c005\RS_ProgramCompatibilityWizard.ps1
ISO-8859 text, with CRLF line terminators
dropped
C:\Windows\Temp\SDIAG_26d32acb-2999-4d66-b897-077572d4c005\TS_ProgramCompatibilityWizard.ps1
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Windows\Temp\SDIAG_26d32acb-2999-4d66-b897-077572d4c005\VF_ProgramCompatibilityWizard.ps1
ISO-8859 text, with CRLF line terminators
dropped
C:\Windows\Temp\SDIAG_26d32acb-2999-4d66-b897-077572d4c005\en-US\CL_LocalizationData.psd1
Little-endian UTF-16 Unicode text, with CRLF, CR line terminators
dropped
C:\Windows\Temp\SDIAG_26d32acb-2999-4d66-b897-077572d4c005\en-US\DiagPackage.dll.mui
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Windows\Temp\SDIAG_26d32acb-2999-4d66-b897-077572d4c005\result\results.xsl
XML 1.0 document, ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Microsoft\Office\14.0\OfficeFileCache\FSD-CNRY.FSD
data
dropped
C:\Users\user\AppData\Local\Microsoft\Office\14.0\OfficeFileCache\FSD-{8A06192A-30A6-47D1-ADF8-054AC9F6B663}.FSD
data
dropped
C:\Users\user\AppData\Local\Microsoft\Office\14.0\OfficeFileCache\FSF-CTBL.FSF
data
dropped
C:\Users\user\AppData\Local\Microsoft\Office\14.0\OfficeFileCache\LocalCacheFileEditManager\FSD-CNRY.FSD
data
dropped
C:\Users\user\AppData\Local\Microsoft\Office\14.0\OfficeFileCache\LocalCacheFileEditManager\FSD-{5D1B35F5-C171-4718-AE70-CD91AAB04010}.FSD
data
dropped
C:\Users\user\AppData\Local\Microsoft\Office\14.0\OfficeFileCache\LocalCacheFileEditManager\FSF-{0E1EEE64-E8C6-4E2A-9759-63CF07FD8988}.FSF
data
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\Glomet[1].htm
HTML document, ASCII text, with very long lines, with CRLF line terminators
downloaded
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\2264EBF3.htm
HTML document, ASCII text, with very long lines, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\6387B6EF.png
PNG image data, 2317 x 3433, 8-bit colormap, non-interlaced
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\72919526.htm
HTML document, ASCII text, with very long lines, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRF{3BCD92F0-1C3B-4D0C-AD4B-E4107D6CB424}.tmp
Composite Document File V2 Document, Cannot read section info
dropped