IOC Report
173347927400d8505e200f1b76c0df0392d3948b50b640983683242dde80f09986d2060a0a419.dat-decoded.exe

loading gif

Files

File Path
Type
Category
Malicious
173347927400d8505e200f1b76c0df0392d3948b50b640983683242dde80f09986d2060a0a419.dat-decoded.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\ProgramData\remcos\logs.dat
data
dropped
malicious

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\173347927400d8505e200f1b76c0df0392d3948b50b640983683242dde80f09986d2060a0a419.dat-decoded.exe
"C:\Users\user\Desktop\173347927400d8505e200f1b76c0df0392d3948b50b640983683242dde80f09986d2060a0a419.dat-decoded.exe"
malicious

URLs

Name
IP
Malicious
ahmedahmed.ddns.net
malicious
http://geoplugin.net/json.gp
unknown
http://geoplugin.net/json.gp/C
unknown

Domains

Name
IP
Malicious
ahmedahmed.ddns.net
0.0.0.0
malicious
fp2e7a.wpc.phicdn.net
192.229.221.95

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\SOFTWARE\Rmc-SEVL3E
exepath
HKEY_CURRENT_USER\SOFTWARE\Rmc-SEVL3E
licence
HKEY_CURRENT_USER\SOFTWARE\Rmc-SEVL3E
time

Memdumps

Base Address
Regiontype
Protect
Malicious
457000
unkown
page readonly
malicious
457000
unkown
page readonly
malicious
86E000
heap
page read and write
malicious
22FF000
stack
page read and write
malicious
82E000
stack
page read and write
19C000
stack
page read and write
666000
heap
page read and write
470000
unkown
page write copy
476000
unkown
page readonly
660000
heap
page read and write
8A2000
heap
page read and write
401000
unkown
page execute read
476000
unkown
page readonly
59E000
stack
page read and write
470000
unkown
page read and write
253F000
stack
page read and write
1F0000
heap
page read and write
86A000
heap
page read and write
8C0000
heap
page read and write
7EC000
stack
page read and write
A5F000
stack
page read and write
400000
unkown
page readonly
2330000
heap
page read and write
860000
heap
page read and write
550000
heap
page read and write
401000
unkown
page execute read
680000
heap
page read and write
62E000
stack
page read and write
473000
unkown
page read and write
263F000
stack
page read and write
7AC000
stack
page read and write
8AC000
heap
page read and write
9C000
stack
page read and write
400000
unkown
page readonly
630000
heap
page read and write
670000
heap
page read and write
243F000
stack
page read and write
There are 27 hidden memdumps, click here to show them.