IOC Report
ASEGNEGROMARZ.exe

loading gifFilesProcessesURLsDomainsIPsRegistryMemdumps642010Label

Files

File Path
Type
Category
Malicious
Download
ASEGNEGROMARZ.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\ProgramData\remcos\logs.dat
data
modified
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9C680Q69\json[1].json
JSON data
dropped
\Device\ConDrv
ISO-8859 text, with CRLF line terminators
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\ASEGNEGROMARZ.exe
"C:\Users\user\Desktop\ASEGNEGROMARZ.exe"
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1

URLs

Name
IP
Malicious
esteesnuevo2025.duckdns.org
malicious
http://geoplugin.net/json.gp
178.237.33.50
http://geoplugin.net/json.gpD
unknown
http://geoplugin.net/json.gpA
unknown
http://geoplugin.net/json.gpg
unknown
http://geoplugin.net/
unknown
http://geoplugin.net/json.gp/C
unknown
http://geoplugin.net/json.gpSystem32
unknown

Domains

Name
IP
Malicious
esteesnuevo2025.duckdns.org
192.159.99.113
malicious
geoplugin.net
178.237.33.50

IPs

IP
Domain
Country
Malicious
192.159.99.113
esteesnuevo2025.duckdns.org
United Kingdom
malicious
178.237.33.50
geoplugin.net
Netherlands

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\SOFTWARE\Rmc-365FYR
exepath
HKEY_CURRENT_USER\SOFTWARE\Rmc-365FYR
licence
HKEY_CURRENT_USER\SOFTWARE\Rmc-365FYR
time
HKEY_CURRENT_USER\SOFTWARE\Rmc-365FYR
UID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System
PromptOnSecureDesktop

Memdumps

Base Address
Regiontype
Protect
Malicious
Download
459000
unkown
page readonly
malicious
7EE000
heap
page read and write
malicious
841000
heap
page read and write
malicious
842000
heap
page read and write
malicious
24BF000
stack
page read and write
malicious
459000
unkown
page readonly
malicious
832000
heap
page read and write
malicious
9DF000
stack
page read and write
869000
heap
page read and write
655000
heap
page read and write
87B000
heap
page read and write
3B91000
heap
page read and write
2AAF000
stack
page read and write
600000
heap
page read and write
790000
heap
page read and write
9C000
stack
page read and write
873000
heap
page read and write
2AEE000
stack
page read and write
660000
heap
page read and write
670000
heap
page read and write
472000
unkown
page write copy
650000
heap
page read and write
478000
unkown
page readonly
5FE000
stack
page read and write
2C2E000
stack
page read and write
823000
heap
page read and write
2D2F000
stack
page read and write
79A000
heap
page read and write
832000
heap
page read and write
329E000
stack
page read and write
2D6C000
stack
page read and write
2FFE000
stack
page read and write
23BE000
stack
page read and write
33B1000
heap
page read and write
855000
heap
page read and write
33B0000
heap
page read and write
7EA000
heap
page read and write
2520000
heap
page read and write
29AC000
stack
page read and write
873000
heap
page read and write
2E6E000
stack
page read and write
7DC000
stack
page read and write
832000
heap
page read and write
ADF000
stack
page read and write
45BA000
heap
page read and write
1F0000
heap
page read and write
870000
heap
page read and write
19C000
stack
page read and write
24FC000
stack
page read and write
472000
unkown
page read and write
339F000
stack
page read and write
3B95000
heap
page read and write
870000
heap
page read and write
315F000
stack
page read and write
400000
unkown
page readonly
401000
unkown
page execute read
87B000
heap
page read and write
862000
heap
page read and write
262F000
stack
page read and write
869000
heap
page read and write
870000
heap
page read and write
869000
heap
page read and write
2EBE000
stack
page read and write
2500000
heap
page read and write
832000
heap
page read and write
40A5000
heap
page read and write
2BEF000
stack
page read and write
855000
heap
page read and write
475000
unkown
page read and write
2FBF000
stack
page read and write
855000
heap
page read and write
823000
heap
page read and write
401000
unkown
page execute read
832000
heap
page read and write
478000
unkown
page readonly
33C0000
heap
page read and write
33C0000
heap
page read and write
560000
heap
page read and write
860000
heap
page read and write
305B000
heap
page read and write
400000
unkown
page readonly
237B000
stack
page read and write
873000
heap
page read and write
7E0000
heap
page read and write
5AC000
stack
page read and write
855000
heap
page read and write
826000
heap
page read and write
3050000
heap
page read and write
There are 78 hidden memdumps, click here to show them.