IOC Report
172200150645e30715396b41ed298fc2fc05d94f3a962536daa72f2c5d72e7d784323a4055802.dat-decoded.exe

loading gif

Files

File Path
Type
Category
Malicious
172200150645e30715396b41ed298fc2fc05d94f3a962536daa72f2c5d72e7d784323a4055802.dat-decoded.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Local\Temp\Notepo\logs.dat
data
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\T9RRWRNL\json[1].json
JSON data
dropped
C:\Users\user\AppData\Local\Temp\bhvE9F8.tmp
Extensible storage engine DataBase, version 0x620, checksum 0x29d2e728, page size 32768, DirtyShutdown, Windows version 10.0
dropped
C:\Users\user\AppData\Local\Temp\fdyvulym
Unicode text, UTF-16, little-endian text, with no line terminators
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\172200150645e30715396b41ed298fc2fc05d94f3a962536daa72f2c5d72e7d784323a4055802.dat-decoded.exe
"C:\Users\user\Desktop\172200150645e30715396b41ed298fc2fc05d94f3a962536daa72f2c5d72e7d784323a4055802.dat-decoded.exe"
malicious
C:\Users\user\Desktop\172200150645e30715396b41ed298fc2fc05d94f3a962536daa72f2c5d72e7d784323a4055802.dat-decoded.exe
C:\Users\user\Desktop\172200150645e30715396b41ed298fc2fc05d94f3a962536daa72f2c5d72e7d784323a4055802.dat-decoded.exe /stext "C:\Users\user\AppData\Local\Temp\fdyvulym"
malicious
C:\Users\user\Desktop\172200150645e30715396b41ed298fc2fc05d94f3a962536daa72f2c5d72e7d784323a4055802.dat-decoded.exe
C:\Users\user\Desktop\172200150645e30715396b41ed298fc2fc05d94f3a962536daa72f2c5d72e7d784323a4055802.dat-decoded.exe /stext "C:\Users\user\AppData\Local\Temp\pgegndrngmr"
malicious
C:\Users\user\Desktop\172200150645e30715396b41ed298fc2fc05d94f3a962536daa72f2c5d72e7d784323a4055802.dat-decoded.exe
C:\Users\user\Desktop\172200150645e30715396b41ed298fc2fc05d94f3a962536daa72f2c5d72e7d784323a4055802.dat-decoded.exe /stext "C:\Users\user\AppData\Local\Temp\rajyovchuujkyh"
malicious

URLs

Name
IP
Malicious
maveing.duckdns.org
malicious
https://M365CDN.nel.measure.office.net/api/report?FrontEnd=VerizonCDNWorldWide&DestinationEndpoint=P
unknown
https://www.office.com/
unknown
http://www.imvu.comr
unknown
http://geoplugin.net/json.gp%
unknown
http://geoplugin.net/json.gpl
unknown
https://fp-afd.azurefd.us/apc/trans.gif?0cf92be82316943650f2ee723bc6949e
unknown
http://www.imvu.com
unknown
http://www.nirsoft.net
unknown
https://aefd.nelreports.net/api/report?cat=bingaotak
unknown
https://deff.nelreports.net/api/report?cat=msn
unknown
http://www.imvu.comhttp://www.ebuddy.comhttps://www.google.com
unknown
http://geoplugin.net/json.gp
178.237.33.50
https://www.google.com
unknown
https://fp-afd.azurefd.us/apc/trans.gif?94fb5ac9609bcb4cda0bf8acf1827073
unknown
https://ecs.nel.measure.office.net?TenantId=Skype&DestinationEndpoint=Edge-Prod-LAX31r5a&FrontEnd=AF
unknown
http://geoplugin.net/
unknown
https://aefd.nelreports.net/api/report?cat=bingaot
unknown
http://geoplugin.net/json.gp/C
unknown
https://maps.windows.com/windows-app-web-link
unknown
http://geoplugin.net/json.gpJ
unknown
https://aefd.nelreports.net/api/report?cat=bingrms
unknown
https://www.google.com/accounts/servicelogin
unknown
https://login.yahoo.com/config/login
unknown
http://www.nirsoft.net/
unknown
http://www.imvu.comata
unknown
http://www.ebuddy.com
unknown
There are 17 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
maveing.duckdns.org
192.3.101.142
malicious
geoplugin.net
178.237.33.50

IPs

IP
Domain
Country
Malicious
192.3.101.142
maveing.duckdns.org
United States
malicious
178.237.33.50
geoplugin.net
Netherlands

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\SOFTWARE\Rmc-F4JFYD
exepath
malicious
HKEY_CURRENT_USER\SOFTWARE\Rmc-F4JFYD
licence
malicious
HKEY_CURRENT_USER\SOFTWARE\Rmc-F4JFYD
time
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
459000
unkown
page readonly
malicious
6EE000
heap
page read and write
malicious
459000
unkown
page readonly
malicious
459000
unkown
page readonly
malicious
459000
unkown
page readonly
malicious
459000
unkown
page readonly
malicious
400000
system
page execute and read and write
624000
heap
page read and write
2233000
heap
page read and write
732000
heap
page read and write
3660000
heap
page read and write
384B000
heap
page read and write
3847000
heap
page read and write
745000
heap
page read and write
21DE000
heap
page read and write
625000
heap
page read and write
758000
heap
page read and write
21F1000
heap
page read and write
3752000
heap
page read and write
625000
heap
page read and write
21D0000
heap
page read and write
3859000
heap
page read and write
3859000
heap
page read and write
401000
unkown
page execute read
19A000
stack
page read and write
624000
heap
page read and write
25D0000
heap
page read and write
21B1000
heap
page read and write
21D1000
heap
page read and write
2233000
heap
page read and write
754000
heap
page read and write
21BF000
heap
page read and write
5B7000
heap
page read and write
21D1000
heap
page read and write
4C0000
heap
page read and write
21D0000
heap
page read and write
732000
heap
page read and write
21C0000
heap
page read and write
21CC000
heap
page read and write
9EE000
heap
page read and write
21BE000
heap
page read and write
2990000
trusted library allocation
page read and write
754000
heap
page read and write
624000
heap
page read and write
745000
heap
page read and write
2290000
trusted library allocation
page read and write
624000
heap
page read and write
2BE6000
heap
page read and write
723000
heap
page read and write
3661000
heap
page read and write
910000
heap
page read and write
471000
unkown
page write copy
21F1000
heap
page read and write
9ED000
heap
page read and write
21B1000
heap
page read and write
3847000
heap
page read and write
21B1000
heap
page read and write
385D000
heap
page read and write
754000
heap
page read and write
21D0000
heap
page read and write
2791000
heap
page read and write
21D0000
heap
page read and write
248F000
stack
page read and write
5F3000
heap
page read and write
624000
heap
page read and write
2340000
heap
page read and write
471000
unkown
page read and write
21BE000
heap
page read and write
76D000
heap
page read and write
46E000
stack
page read and write
21EA000
heap
page read and write
478000
unkown
page readonly
758000
heap
page read and write
471000
unkown
page write copy
4BE000
stack
page read and write
732000
heap
page read and write
8FF000
stack
page read and write
624000
heap
page read and write
5B0000
heap
page read and write
2D03000
heap
page read and write
1F0000
heap
page read and write
234F000
stack
page read and write
745000
heap
page read and write
2990000
trusted library allocation
page read and write
21D0000
heap
page read and write
21EB000
heap
page read and write
471000
unkown
page write copy
9C000
stack
page read and write
768000
heap
page read and write
21B1000
heap
page read and write
2990000
trusted library allocation
page read and write
2A70000
heap
page read and write
9C000
stack
page read and write
3867000
heap
page read and write
4C4000
heap
page read and write
2AEA000
heap
page read and write
21C5000
heap
page read and write
9EE000
heap
page read and write
25A0000
heap
page read and write
21CB000
heap
page read and write
2AE9000
heap
page read and write
913000
heap
page read and write
21A0000
heap
page read and write
4C4000
heap
page read and write
2802000
heap
page read and write
5D0000
heap
page read and write
5C0000
heap
page read and write
4C4000
heap
page read and write
1F0000
heap
page read and write
745000
heap
page read and write
6EA000
heap
page read and write
723000
heap
page read and write
401000
unkown
page execute read
21C5000
heap
page read and write
473000
system
page execute and read and write
8CF000
stack
page read and write
21B1000
heap
page read and write
625000
heap
page read and write
732000
heap
page read and write
625000
heap
page read and write
528000
heap
page read and write
21B1000
heap
page read and write
395D000
unclassified section
page execute and read and write
2250000
heap
page read and write
4C4000
heap
page read and write
4C4000
heap
page read and write
4AE000
stack
page read and write
21D1000
heap
page read and write
21C2000
heap
page read and write
5C0000
heap
page read and write
238C000
stack
page read and write
2215000
heap
page read and write
400000
unkown
page readonly
39D6000
unclassified section
page execute and read and write
2798000
heap
page read and write
21C0000
heap
page read and write
624000
heap
page read and write
723000
heap
page read and write
37FC000
heap
page read and write
21BC000
heap
page read and write
3980000
unclassified section
page execute and read and write
3847000
heap
page read and write
299D000
heap
page read and write
21C5000
heap
page read and write
21B8000
heap
page read and write
21AC000
heap
page read and write
459000
system
page execute and read and write
21C0000
heap
page read and write
732000
heap
page read and write
21F7000
heap
page read and write
21D3000
heap
page read and write
4C4000
heap
page read and write
474000
unkown
page read and write
2990000
trusted library allocation
page read and write
21D0000
heap
page read and write
21D2000
heap
page read and write
5CD000
heap
page read and write
3847000
heap
page read and write
272F000
stack
page read and write
21C0000
heap
page read and write
21CC000
heap
page read and write
401000
unkown
page execute read
21E9000
heap
page read and write
322F000
stack
page read and write
20FE000
stack
page read and write
25A1000
heap
page read and write
21CC000
heap
page read and write
754000
heap
page read and write
401000
unkown
page execute read
732000
heap
page read and write
21B9000
heap
page read and write
500000
heap
page read and write
269F000
stack
page read and write
21BC000
heap
page read and write
223C000
stack
page read and write
2799000
heap
page read and write
2AD3000
heap
page read and write
625000
heap
page read and write
5CD000
heap
page read and write
780000
heap
page read and write
5D7000
heap
page read and write
21C0000
heap
page read and write
9BC000
heap
page read and write
312E000
stack
page read and write
384B000
heap
page read and write
2088000
heap
page read and write
4BE000
stack
page read and write
745000
heap
page read and write
758000
heap
page read and write
25CF000
stack
page read and write
2691000
heap
page read and write
21BC000
heap
page read and write
21D5000
heap
page read and write
400000
unkown
page readonly
384B000
heap
page read and write
7A9000
heap
page read and write
754000
heap
page read and write
21CC000
heap
page read and write
624000
heap
page read and write
21BE000
heap
page read and write
21E9000
heap
page read and write
4C4000
heap
page read and write
21C2000
heap
page read and write
4B0000
heap
page read and write
923000
heap
page read and write
758000
heap
page read and write
758000
heap
page read and write
7FF000
stack
page read and write
3845000
heap
page read and write
21D2000
heap
page read and write
745000
heap
page read and write
21F1000
heap
page read and write
3753000
heap
page read and write
732000
heap
page read and write
21E2000
heap
page read and write
21C0000
heap
page read and write
21B1000
heap
page read and write
25A1000
heap
page read and write
3973000
unclassified section
page execute and read and write
21AD000
heap
page read and write
400000
unkown
page readonly
920000
trusted library allocation
page read and write
10001000
direct allocation
page execute and read and write
21D3000
heap
page read and write
4C4000
heap
page read and write
21D0000
heap
page read and write
21B1000
heap
page read and write
780000
heap
page read and write
21BC000
heap
page read and write
19C000
stack
page read and write
21AE000
heap
page read and write
3845000
heap
page read and write
2B62000
heap
page read and write
768000
heap
page read and write
4C4000
heap
page read and write
768000
heap
page read and write
17C000
stack
page read and write
45C000
system
page execute and read and write
3845000
heap
page read and write
76B000
heap
page read and write
624000
heap
page read and write
21BC000
heap
page read and write
754000
heap
page read and write
21C0000
heap
page read and write
21E8000
heap
page read and write
21B8000
heap
page read and write
401000
unkown
page execute read
2A71000
heap
page read and write
620000
heap
page read and write
768000
heap
page read and write
478000
unkown
page readonly
21C0000
heap
page read and write
2990000
trusted library allocation
page read and write
2AE8000
heap
page read and write
76B000
heap
page read and write
3847000
heap
page read and write
4C4000
heap
page read and write
39F0000
unclassified section
page execute and read and write
21D2000
heap
page read and write
5F1000
heap
page read and write
21D3000
heap
page read and write
262E000
stack
page read and write
21BE000
heap
page read and write
21D0000
heap
page read and write
2803000
heap
page read and write
384B000
heap
page read and write
3959000
unclassified section
page execute and read and write
758000
heap
page read and write
21B4000
heap
page read and write
745000
heap
page read and write
774000
heap
page read and write
21D0000
heap
page read and write
754000
heap
page read and write
21E2000
heap
page read and write
478000
unkown
page readonly
384B000
heap
page read and write
456000
system
page execute and read and write
21D2000
heap
page read and write
1F0000
heap
page read and write
3900000
unclassified section
page execute and read and write
754000
heap
page read and write
723000
heap
page read and write
758000
heap
page read and write
9C000
stack
page read and write
21D3000
heap
page read and write
21C5000
heap
page read and write
530000
heap
page read and write
4C4000
heap
page read and write
21BE000
heap
page read and write
21F7000
heap
page read and write
21C1000
heap
page read and write
758000
heap
page read and write
4C4000
heap
page read and write
207F000
stack
page read and write
21D0000
heap
page read and write
21B1000
heap
page read and write
400000
system
page execute and read and write
41B000
system
page execute and read and write
2691000
heap
page read and write
10016000
direct allocation
page execute and read and write
625000
heap
page read and write
624000
heap
page read and write
598000
heap
page read and write
37FB000
heap
page read and write
21D0000
heap
page read and write
21C8000
heap
page read and write
21C0000
heap
page read and write
21C0000
heap
page read and write
723000
heap
page read and write
39DC000
unclassified section
page execute and read and write
21B9000
heap
page read and write
9B0000
heap
page read and write
3753000
heap
page read and write
732000
heap
page read and write
21D0000
heap
page read and write
21B1000
heap
page read and write
2CF2000
heap
page read and write
470000
heap
page read and write
21D0000
heap
page read and write
625000
heap
page read and write
2790000
heap
page read and write
9B3000
heap
page read and write
21D0000
heap
page read and write
85F000
stack
page read and write
768000
heap
page read and write
21C0000
heap
page read and write
9E6000
heap
page read and write
732000
heap
page read and write
21EF000
heap
page read and write
177000
stack
page read and write
478000
unkown
page readonly
2699000
heap
page read and write
624000
heap
page read and write
4C4000
heap
page read and write
2802000
heap
page read and write
2799000
heap
page read and write
21C0000
heap
page read and write
36DA000
heap
page read and write
745000
heap
page read and write
1F0000
heap
page read and write
400000
unkown
page readonly
57E000
stack
page read and write
299D000
heap
page read and write
774000
heap
page read and write
3661000
heap
page read and write
929000
heap
page read and write
2ADE000
heap
page read and write
24CE000
stack
page read and write
21DA000
heap
page read and write
21C1000
heap
page read and write
21CC000
heap
page read and write
4C4000
heap
page read and write
2AE8000
heap
page read and write
18F000
stack
page read and write
21AC000
heap
page read and write
723000
heap
page read and write
21D0000
heap
page read and write
21D5000
heap
page read and write
21B1000
heap
page read and write
21D0000
heap
page read and write
21F1000
heap
page read and write
754000
heap
page read and write
21D2000
heap
page read and write
21FF000
stack
page read and write
3845000
heap
page read and write
9BC000
heap
page read and write
758000
heap
page read and write
560000
heap
page read and write
6E0000
heap
page read and write
2990000
trusted library allocation
page read and write
745000
heap
page read and write
745000
heap
page read and write
220D000
heap
page read and write
19C000
stack
page read and write
780000
heap
page read and write
21D0000
heap
page read and write
624000
heap
page read and write
37CB000
heap
page read and write
2209000
heap
page read and write
21B1000
heap
page read and write
383B000
heap
page read and write
9C000
stack
page read and write
768000
heap
page read and write
21F7000
heap
page read and write
21D1000
heap
page read and write
4C4000
heap
page read and write
21C1000
heap
page read and write
3A0B000
unclassified section
page execute and read and write
4FE000
stack
page read and write
768000
heap
page read and write
2803000
heap
page read and write
21BC000
heap
page read and write
400000
system
page execute and read and write
471000
unkown
page write copy
754000
heap
page read and write
384B000
heap
page read and write
624000
heap
page read and write
758000
heap
page read and write
624000
heap
page read and write
10000000
direct allocation
page read and write
768000
heap
page read and write
2240000
heap
page read and write
590000
heap
page read and write
45D000
system
page execute and read and write
21B9000
heap
page read and write
2233000
heap
page read and write
758000
heap
page read and write
2ADA000
heap
page read and write
2A71000
heap
page read and write
21C2000
heap
page read and write
21DA000
heap
page read and write
21C0000
heap
page read and write
8E0000
heap
page read and write
400000
unkown
page readonly
625000
heap
page read and write
2AEA000
heap
page read and write
21F3000
heap
page read and write
21C2000
heap
page read and write
21F1000
heap
page read and write
2690000
heap
page read and write
21AC000
heap
page read and write
4C4000
heap
page read and write
7CD000
stack
page read and write
520000
heap
page read and write
3845000
heap
page read and write
21BE000
heap
page read and write
21C0000
heap
page read and write
21C5000
heap
page read and write
37CB000
heap
page read and write
774000
heap
page read and write
21C0000
heap
page read and write
768000
heap
page read and write
2B62000
heap
page read and write
745000
heap
page read and write
21AC000
heap
page read and write
774000
heap
page read and write
768000
heap
page read and write
9E0000
heap
page read and write
21DA000
heap
page read and write
21B1000
heap
page read and write
76D000
heap
page read and write
768000
heap
page read and write
723000
heap
page read and write
2AD9000
heap
page read and write
21C1000
heap
page read and write
2190000
heap
page read and write
21C0000
heap
page read and write
727000
heap
page read and write
380B000
heap
page read and write
72B000
heap
page read and write
221C000
heap
page read and write
2BF4000
heap
page read and write
21D0000
heap
page read and write
754000
heap
page read and write
5AE000
stack
page read and write
5C3000
heap
page read and write
478000
unkown
page readonly
3847000
heap
page read and write
624000
heap
page read and write
21D3000
heap
page read and write
774000
heap
page read and write
21C0000
heap
page read and write
4C4000
heap
page read and write
2691000
heap
page read and write
3845000
heap
page read and write
624000
heap
page read and write
76D000
heap
page read and write
21D0000
heap
page read and write
21C0000
heap
page read and write
193000
stack
page read and write
There are 460 hidden memdumps, click here to show them.