IOC Report
viDOiTPoMl.exe

loading gifFilesProcessesURLsDomainsIPsRegistryMemdumps4321020102Label

Files

File Path
Type
Category
Malicious
Download
viDOiTPoMl.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\ProgramData\remcos\logs.dat
data
dropped
malicious

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\viDOiTPoMl.exe
"C:\Users\user\Desktop\viDOiTPoMl.exe"
malicious

URLs

Name
IP
Malicious
ramcxx.duckdns.org
malicious
http://geoplugin.net/json.gp
unknown
http://geoplugin.net/json.gp/C
unknown

Domains

Name
IP
Malicious
ramcxx.duckdns.org
192.169.69.26
malicious

IPs

IP
Domain
Country
Malicious
192.169.69.26
ramcxx.duckdns.org
United States
malicious

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\SOFTWARE\Rmc-B6SAO9
exepath
HKEY_CURRENT_USER\SOFTWARE\Rmc-B6SAO9
licence
HKEY_CURRENT_USER\SOFTWARE\Rmc-B6SAO9
time

Memdumps

Base Address
Regiontype
Protect
Malicious
Download
459000
unkown
page readonly
malicious
459000
unkown
page readonly
malicious
49E000
heap
page read and write
malicious
22EF000
stack
page read and write
malicious
216C000
stack
page read and write
21AE000
stack
page read and write
1F0000
heap
page read and write
23EF000
stack
page read and write
400000
unkown
page readonly
400000
unkown
page readonly
9C000
stack
page read and write
26EF000
unkown
page read and write
478000
unkown
page readonly
25EF000
stack
page read and write
7BE000
stack
page read and write
478000
unkown
page readonly
490000
heap
page read and write
212C000
stack
page read and write
670000
heap
page read and write
665000
heap
page read and write
24EF000
stack
page read and write
401000
unkown
page execute read
690000
heap
page read and write
680000
heap
page read and write
471000
unkown
page write copy
19C000
stack
page read and write
49A000
heap
page read and write
8FE000
stack
page read and write
20EE000
stack
page read and write
474000
unkown
page read and write
401000
unkown
page execute read
660000
heap
page read and write
8BF000
stack
page read and write
471000
unkown
page read and write
21E0000
heap
page read and write
21B0000
heap
page read and write
There are 26 hidden memdumps, click here to show them.