IOC Report
1733490559d59c04cc496d19f458945b96e65fd57801bd9b53502be73c34ff8d8deb937e45230.dat-decoded.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\1733490559d59c04cc496d19f458945b96e65fd57801bd9b53502be73c34ff8d8deb937e45230.dat-decoded.exe
"C:\Users\user\Desktop\1733490559d59c04cc496d19f458945b96e65fd57801bd9b53502be73c34ff8d8deb937e45230.dat-decoded.exe"
malicious

URLs

Name
IP
Malicious
http://geoplugin.net/json.gp
unknown
http://geoplugin.net/json.gp/C
unknown

IPs

IP
Domain
Country
Malicious
104.243.246.120
unknown
United States
malicious

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\SOFTWARE\Rmc-4NJUM7
exepath
malicious
HKEY_CURRENT_USER\SOFTWARE\Rmc-4NJUM7
licence
malicious
HKEY_CURRENT_USER\SOFTWARE\Rmc-4NJUM7
time
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
457000
unkown
page readonly
malicious
457000
unkown
page readonly
malicious
5CE000
heap
page read and write
malicious
248F000
stack
page read and write
5C0000
heap
page read and write
470000
unkown
page write copy
2280000
heap
page read and write
556000
heap
page read and write
476000
unkown
page readonly
80E000
stack
page read and write
2290000
heap
page read and write
400000
unkown
page readonly
473000
unkown
page read and write
9C000
stack
page read and write
560000
heap
page read and write
5CA000
heap
page read and write
20DE000
stack
page read and write
470000
unkown
page read and write
21E0000
heap
page read and write
401000
unkown
page execute read
22A0000
heap
page read and write
401000
unkown
page execute read
5AE000
stack
page read and write
550000
heap
page read and write
1F0000
heap
page read and write
476000
unkown
page readonly
400000
unkown
page readonly
7BF000
stack
page read and write
21DF000
stack
page read and write
19D000
stack
page read and write
There are 20 hidden memdumps, click here to show them.