IOC Report
6b585caaf4299c406c45a3beb76a8624d159404e1aac48a292976119c6d9b72c_payload.exe

loading gif

Files

File Path
Type
Category
Malicious
6b585caaf4299c406c45a3beb76a8624d159404e1aac48a292976119c6d9b72c_payload.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\ProgramData\remcos\logs.dat
data
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3D003UC5\json[1].json
JSON data
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\6b585caaf4299c406c45a3beb76a8624d159404e1aac48a292976119c6d9b72c_payload.exe
"C:\Users\user\Desktop\6b585caaf4299c406c45a3beb76a8624d159404e1aac48a292976119c6d9b72c_payload.exe"
malicious

URLs

Name
IP
Malicious
94.156.69.93
malicious
http://geoplugin.net/json.gp
178.237.33.50
http://geoplugin.net/json.gpr
unknown
http://geoplugin.net/
unknown
http://geoplugin.net/json.gp/C
unknown
http://geoplugin.net/json.gpl
unknown

Domains

Name
IP
Malicious
geoplugin.net
178.237.33.50

IPs

IP
Domain
Country
Malicious
94.156.69.93
unknown
Bulgaria
malicious
178.237.33.50
geoplugin.net
Netherlands

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\SOFTWARE\Rmc-HKC0PV
exepath
HKEY_CURRENT_USER\SOFTWARE\Rmc-HKC0PV
licence
HKEY_CURRENT_USER\SOFTWARE\Rmc-HKC0PV
time

Memdumps

Base Address
Regiontype
Protect
Malicious
4DE000
heap
page read and write
malicious
459000
unkown
page readonly
malicious
459000
unkown
page readonly
malicious
237F000
stack
page read and write
malicious
51C000
heap
page read and write
malicious
474000
unkown
page read and write
54D000
heap
page read and write
558000
heap
page read and write
471000
unkown
page read and write
9C000
stack
page read and write
4DA000
heap
page read and write
401000
unkown
page execute read
720000
heap
page read and write
60E000
stack
page read and write
471000
unkown
page write copy
400000
unkown
page readonly
4B0000
heap
page read and write
227E000
stack
page read and write
23BC000
stack
page read and write
322F000
stack
page read and write
287F000
stack
page read and write
263E000
stack
page read and write
558000
heap
page read and write
400000
unkown
page readonly
51C000
heap
page read and write
25FF000
stack
page read and write
558000
heap
page read and write
1F0000
heap
page read and write
54B000
heap
page read and write
91F000
stack
page read and write
610000
heap
page read and write
53D000
heap
page read and write
273F000
stack
page read and write
24BF000
stack
page read and write
24FC000
stack
page read and write
478000
unkown
page readonly
53D000
heap
page read and write
478000
unkown
page readonly
401000
unkown
page execute read
490000
heap
page read and write
19D000
stack
page read and write
647000
heap
page read and write
277E000
stack
page read and write
640000
heap
page read and write
4D0000
heap
page read and write
312E000
stack
page read and write
There are 36 hidden memdumps, click here to show them.