IOC Report
1733479274764e7b4f05da07e19f78d3cf31f2aafa2f5d7a78af2fd18749e25dbbc1473b66785.dat-decoded.exe

loading gif

Files

File Path
Type
Category
Malicious
1733479274764e7b4f05da07e19f78d3cf31f2aafa2f5d7a78af2fd18749e25dbbc1473b66785.dat-decoded.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\T9RRWRNL\json[1].json
JSON data
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\1733479274764e7b4f05da07e19f78d3cf31f2aafa2f5d7a78af2fd18749e25dbbc1473b66785.dat-decoded.exe
"C:\Users\user\Desktop\1733479274764e7b4f05da07e19f78d3cf31f2aafa2f5d7a78af2fd18749e25dbbc1473b66785.dat-decoded.exe"
malicious

URLs

Name
IP
Malicious
http://geoplugin.net/json.gp
178.237.33.50
http://geoplugin.net/json.gpQ
unknown
http://geoplugin.net/json.gpV
unknown
http://geoplugin.net/json.gp/C
unknown
http://geoplugin.net/json.gpSystem32
unknown
http://geoplugin.net/json.gpll
unknown

Domains

Name
IP
Malicious
geoplugin.net
178.237.33.50

IPs

IP
Domain
Country
Malicious
148.113.165.11
unknown
United States
malicious
178.237.33.50
geoplugin.net
Netherlands

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\SOFTWARE\asasasa-H4TBM8
exepath
HKEY_CURRENT_USER\SOFTWARE\asasasa-H4TBM8
licence
HKEY_CURRENT_USER\SOFTWARE\asasasa-H4TBM8
time

Memdumps

Base Address
Regiontype
Protect
Malicious
457000
unkown
page readonly
malicious
457000
unkown
page readonly
malicious
70E000
heap
page read and write
malicious
1F0000
heap
page read and write
570000
heap
page read and write
2D5E000
stack
page read and write
2300000
heap
page read and write
749000
heap
page read and write
782000
heap
page read and write
70A000
heap
page read and write
700000
heap
page read and write
401000
unkown
page execute read
476000
unkown
page readonly
401000
unkown
page execute read
550000
heap
page read and write
19D000
stack
page read and write
777000
heap
page read and write
782000
heap
page read and write
470000
unkown
page write copy
473000
unkown
page read and write
76C000
heap
page read and write
470000
unkown
page read and write
400000
unkown
page readonly
250F000
stack
page read and write
2E5F000
stack
page read and write
75A000
heap
page read and write
476000
unkown
page readonly
6CF000
stack
page read and write
9C000
stack
page read and write
3270000
heap
page read and write
5CE000
stack
page read and write
775000
heap
page read and write
240F000
stack
page read and write
2220000
heap
page read and write
3280000
heap
page read and write
76C000
heap
page read and write
782000
heap
page read and write
400000
unkown
page readonly
749000
heap
page read and write
75A000
heap
page read and write
227E000
stack
page read and write
577000
heap
page read and write
221E000
stack
page read and write
There are 33 hidden memdumps, click here to show them.