IOC Report
1722001145c8336cb6887f0bbe0b12744f5c43638979603a57a5fc96eb7f34015fb312b4f7920.dat-decoded.exe

loading gif

Files

File Path
Type
Category
Malicious
1722001145c8336cb6887f0bbe0b12744f5c43638979603a57a5fc96eb7f34015fb312b4f7920.dat-decoded.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\T9RRWRNL\json[1].json
JSON data
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\1722001145c8336cb6887f0bbe0b12744f5c43638979603a57a5fc96eb7f34015fb312b4f7920.dat-decoded.exe
"C:\Users\user\Desktop\1722001145c8336cb6887f0bbe0b12744f5c43638979603a57a5fc96eb7f34015fb312b4f7920.dat-decoded.exe"
malicious

URLs

Name
IP
Malicious
2024remcmon.duckdns.org
malicious
http://geoplugin.net/json.gp
178.237.33.50
http://geoplugin.net/2
unknown
http://geoplugin.net/
unknown
http://geoplugin.net/json.gpU
unknown
http://geoplugin.net/json.gp/C
unknown
http://geoplugin.net/json.gpl
unknown
http://geoplugin.net/json.gpK
unknown
http://geoplugin.net/json.gpSystem32
unknown

Domains

Name
IP
Malicious
2024remcmon.duckdns.org
192.210.214.9
malicious
geoplugin.net
178.237.33.50

IPs

IP
Domain
Country
Malicious
192.210.214.9
2024remcmon.duckdns.org
United States
malicious
178.237.33.50
geoplugin.net
Netherlands

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\SOFTWARE\Rmc-R2I0JW
exepath
malicious
HKEY_CURRENT_USER\SOFTWARE\Rmc-R2I0JW
licence
malicious
HKEY_CURRENT_USER\SOFTWARE\Rmc-R2I0JW
time
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
459000
unkown
page readonly
malicious
459000
unkown
page readonly
malicious
61E000
heap
page read and write
malicious
660000
heap
page read and write
400000
unkown
page readonly
478000
unkown
page readonly
660000
heap
page read and write
698000
heap
page read and write
401000
unkown
page execute read
5B7000
heap
page read and write
680000
heap
page read and write
471000
unkown
page read and write
680000
heap
page read and write
401000
unkown
page execute read
225E000
stack
page read and write
698000
heap
page read and write
21F0000
heap
page read and write
400000
unkown
page readonly
692000
heap
page read and write
61A000
heap
page read and write
2210000
heap
page read and write
689000
heap
page read and write
249F000
stack
page read and write
651000
heap
page read and write
2E6F000
stack
page read and write
689000
heap
page read and write
5AE000
stack
page read and write
474000
unkown
page read and write
471000
unkown
page write copy
235F000
stack
page read and write
1F0000
heap
page read and write
239E000
stack
page read and write
2D6E000
stack
page read and write
698000
heap
page read and write
478000
unkown
page readonly
710000
heap
page read and write
560000
heap
page read and write
90F000
stack
page read and write
610000
heap
page read and write
690000
heap
page read and write
5B0000
heap
page read and write
9C000
stack
page read and write
19C000
stack
page read and write
There are 33 hidden memdumps, click here to show them.