IOC Report
172926254156daf582728190320bacb622ccd105a50446fe4e74bbec68be10e3a78d1b71e6763.dat-decoded.exe

loading gif

Files

File Path
Type
Category
Malicious
172926254156daf582728190320bacb622ccd105a50446fe4e74bbec68be10e3a78d1b71e6763.dat-decoded.exe
PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\T9RRWRNL\json[1].json
JSON data
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\172926254156daf582728190320bacb622ccd105a50446fe4e74bbec68be10e3a78d1b71e6763.dat-decoded.exe
"C:\Users\user\Desktop\172926254156daf582728190320bacb622ccd105a50446fe4e74bbec68be10e3a78d1b71e6763.dat-decoded.exe"
malicious

URLs

Name
IP
Malicious
http://geoplugin.net/json.gp
178.237.33.50
http://geoplugin.net/O
unknown
http://geoplugin.net/json.gpq
unknown
http://geoplugin.net/json.gpE
unknown
http://geoplugin.net/json.gp/C
unknown

Domains

Name
IP
Malicious
198.187.3.20.in-addr.arpa
unknown
malicious
geoplugin.net
178.237.33.50

IPs

IP
Domain
Country
Malicious
23.227.193.34
unknown
United States
malicious
178.237.33.50
geoplugin.net
Netherlands

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\SOFTWARE\Rmc-13UDOF
exepath
malicious
HKEY_CURRENT_USER\SOFTWARE\Rmc-13UDOF
licence
malicious
HKEY_CURRENT_USER\SOFTWARE\Rmc-13UDOF
time
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
68E000
heap
page read and write
malicious
401000
unkown
page execute and read and write
malicious
228C000
heap
page read and write
707000
heap
page read and write
2280000
heap
page read and write
485000
unkown
page write copy
707000
heap
page read and write
650000
heap
page read and write
6CE000
heap
page read and write
64E000
stack
page read and write
6F8000
heap
page read and write
2D2E000
stack
page read and write
560000
heap
page read and write
6EF000
heap
page read and write
707000
heap
page read and write
6BF000
heap
page read and write
6F8000
heap
page read and write
478000
unkown
page execute and read and write
6CE000
heap
page read and write
1F0000
heap
page read and write
247F000
stack
page read and write
B60000
heap
page read and write
400000
unkown
page readonly
700000
heap
page read and write
400000
unkown
page readonly
87F000
stack
page read and write
719000
heap
page read and write
227F000
stack
page read and write
70F000
heap
page read and write
719000
heap
page read and write
5BE000
stack
page read and write
2E2F000
stack
page read and write
680000
heap
page read and write
576000
heap
page read and write
474000
unkown
page execute and read and write
6FE000
heap
page read and write
482000
unkown
page execute and read and write
68A000
heap
page read and write
B4E000
stack
page read and write
9C000
stack
page read and write
484000
unkown
page execute and write copy
570000
heap
page read and write
47D000
unkown
page execute and read and write
485000
unkown
page read and write
70F000
heap
page read and write
471000
unkown
page execute and read and write
6EF000
heap
page read and write
719000
heap
page read and write
19D000
stack
page read and write
44F000
unkown
page execute and write copy
70F000
heap
page read and write
There are 41 hidden memdumps, click here to show them.