IOC Report
1733479268bef4923665f47803580ac81a0b879268a546c8c91763e06ee07a9566a58cd1ec966.dat-decoded.exe

loading gif

Files

File Path
Type
Category
Malicious
1733479268bef4923665f47803580ac81a0b879268a546c8c91763e06ee07a9566a58cd1ec966.dat-decoded.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\ProgramData\remcos\logs.dat
data
dropped
malicious

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\1733479268bef4923665f47803580ac81a0b879268a546c8c91763e06ee07a9566a58cd1ec966.dat-decoded.exe
"C:\Users\user\Desktop\1733479268bef4923665f47803580ac81a0b879268a546c8c91763e06ee07a9566a58cd1ec966.dat-decoded.exe"
malicious

URLs

Name
IP
Malicious
lewisham1122.ddnsking.com
malicious
http://geoplugin.net/json.gp
unknown
http://geoplugin.net/json.gp/C
unknown

Domains

Name
IP
Malicious
lewisham1122.ddnsking.com
0.0.0.0
malicious

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\SOFTWARE\Rmc-L31JDJ
exepath
HKEY_CURRENT_USER\SOFTWARE\Rmc-L31JDJ
licence
HKEY_CURRENT_USER\SOFTWARE\Rmc-L31JDJ
time

Memdumps

Base Address
Regiontype
Protect
Malicious
5CE000
heap
page read and write
malicious
222F000
stack
page read and write
malicious
457000
unkown
page readonly
malicious
457000
unkown
page readonly
malicious
470000
unkown
page write copy
476000
unkown
page readonly
520000
heap
page read and write
19C000
stack
page read and write
480000
heap
page read and write
400000
unkown
page readonly
536000
heap
page read and write
400000
unkown
page readonly
7A0000
heap
page read and write
24AE000
stack
page read and write
57E000
stack
page read and write
5CA000
heap
page read and write
61F000
heap
page read and write
232F000
stack
page read and write
618000
heap
page read and write
5C0000
heap
page read and write
5BC000
stack
page read and write
60C000
heap
page read and write
473000
unkown
page read and write
476000
unkown
page readonly
9C000
stack
page read and write
401000
unkown
page execute read
790000
heap
page read and write
401000
unkown
page execute read
236C000
stack
page read and write
98F000
stack
page read and write
25AF000
stack
page read and write
246F000
stack
page read and write
1F0000
heap
page read and write
4CE000
stack
page read and write
470000
unkown
page read and write
530000
heap
page read and write
25B0000
heap
page read and write
There are 27 hidden memdumps, click here to show them.