IOC Report
1_13904442253.xla.xlsx

loading gif

Files

File Path
Type
Category
Malicious
1_13904442253.xla.xlsx
Composite Document File V2 Document, Little Endian, Os: Windows, Version 5.1, Code page: 1252, Author: a.asghari, Last Saved By: ali, Name of Creating Application: Microsoft Excel, Create Time/Date: Tue Sep 14 13:30:26 2004, Last Saved Time/Date: Tue Sep 9 18:31:55 2008, Security: 0
initial sample
malicious
C:\Users\user\Desktop\~$1_13904442253.xla.xlsx
data
dropped
malicious
C:\Users\user\AppData\Local\Temp\~DF4E6106C13B7F04D6.TMP
data
dropped
C:\Users\user\AppData\Local\Temp\~DFAB23D18ACD7A39C8.TMP
data
dropped
C:\Users\user\AppData\Local\Temp\~DFC6228DFBF7598270.TMP
data
dropped
C:\Users\user\Desktop\1_13904442253.xla.xls
Composite Document File V2 Document, Little Endian, Os: Windows, Version 5.1, Code page: 1252, Author: a.asghari, Last Saved By: ali, Name of Creating Application: Microsoft Excel, Create Time/Date: Tue Sep 14 13:30:26 2004, Last Saved Time/Date: Tue Sep 9 18:31:55 2008, Security: 0
dropped
C:\Users\user\Desktop\5EEB3888.tmp (copy)
Composite Document File V2 Document, Little Endian, Os: Windows, Version 5.1, Code page: 1252, Author: a.asghari, Last Saved By: ali, Name of Creating Application: Microsoft Excel, Create Time/Date: Tue Sep 14 13:30:26 2004, Last Saved Time/Date: Tue Sep 9 18:31:55 2008, Security: 0
dropped
C:\Users\user\Desktop\96730000
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, Code page: 1252, Author: a.asghari, Last Saved By: user, Name of Creating Application: Microsoft Excel, Create Time/Date: Tue Sep 14 13:30:26 2004, Last Saved Time/Date: Tue Oct 1 06:41:51 2024, Security: 0
dropped
C:\Users\user\Desktop\96730000:Zone.Identifier
ASCII text, with CRLF line terminators
modified

Processes

Path
Cmdline
Malicious
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
"C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /automation -Embedding

URLs

Name
IP
Malicious
http://sakhteman.wordpress.cxom
unknown
http://sakhteman.wordpress.co
unknown
http://sakhteman.wordpress.comb
unknown
http://sakhteman.wordpress.com
unknown

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
>0/
HKEY_CURRENT_USER\Software\Microsoft\Shared Tools\Outlook\Journaling\Microsoft Excel
Enabled
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel
MTTT
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
l5/
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Place MRU
Max Display
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Max Display
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 1
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 2
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 3
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 4
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 5
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 6
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 7
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 8
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 9
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 10
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 11
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 12
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 13
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 14
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 15
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 16
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 17
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 18
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 19
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\file mru
Item 20
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Security\Trusted Documents
LastPurgeTime
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
EXCELFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
ProductFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000100000000F01FEC\Usage
VBAFiles
There are 23 hidden registries, click here to show them.