IOC Report
FdSJYyDayo.exe

loading gif

Files

File Path
Type
Category
Malicious
FdSJYyDayo.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\ProgramData\27 de Junio\27 de Junio.exe
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\ProgramData\27 de Junio\27 de Junio.exe:Zone.Identifier
ASCII text, with CRLF line terminators
modified
malicious
C:\ProgramData\remcos\logs.dat
data
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3D003UC5\json[1].json
JSON data
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\FdSJYyDayo.exe
"C:\Users\user\Desktop\FdSJYyDayo.exe"
malicious
C:\ProgramData\27 de Junio\27 de Junio.exe
"C:\ProgramData\27 de Junio\27 de Junio.exe"
malicious
C:\ProgramData\27 de Junio\27 de Junio.exe
"C:\ProgramData\27 de Junio\27 de Junio.exe"
malicious
C:\ProgramData\27 de Junio\27 de Junio.exe
"C:\ProgramData\27 de Junio\27 de Junio.exe"
malicious
C:\ProgramData\27 de Junio\27 de Junio.exe
"C:\ProgramData\27 de Junio\27 de Junio.exe"
malicious

URLs

Name
IP
Malicious
eslibre9889.dynuddns.com
malicious
http://geoplugin.net/json.gp
178.237.33.50
http://geoplugin.net/json.gp#z
unknown
http://geoplugin.net/json.gpn.net/Eq
unknown
http://geoplugin.net/
unknown
http://geoplugin.net/json.gpQz
unknown
http://geoplugin.net/json.gp/C
unknown

Domains

Name
IP
Malicious
colombiaeslibre9889.dynuddns.com
190.70.119.188
malicious
geoplugin.net
178.237.33.50

IPs

IP
Domain
Country
Malicious
190.70.119.188
colombiaeslibre9889.dynuddns.com
Colombia
malicious
178.237.33.50
geoplugin.net
Netherlands

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Rmc-IN9IWC
malicious
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run
Rmc-IN9IWC
HKEY_CURRENT_USER\SOFTWARE\Rmc-IN9IWC
exepath
HKEY_CURRENT_USER\SOFTWARE\Rmc-IN9IWC
licence
HKEY_CURRENT_USER\SOFTWARE\Rmc-IN9IWC
time

Memdumps

Base Address
Regiontype
Protect
Malicious
5B1000
heap
page read and write
malicious
459000
unkown
page readonly
malicious
528000
heap
page read and write
malicious
459000
unkown
page readonly
malicious
21FF000
stack
page read and write
malicious
459000
unkown
page readonly
malicious
459000
unkown
page readonly
malicious
459000
unkown
page readonly
malicious
459000
unkown
page readonly
malicious
72E000
heap
page read and write
malicious
459000
unkown
page readonly
malicious
5FA000
heap
page read and write
malicious
56E000
heap
page read and write
malicious
750000
heap
page read and write
malicious
6E7000
heap
page read and write
malicious
459000
unkown
page readonly
malicious
459000
unkown
page readonly
malicious
459000
unkown
page readonly
malicious
471000
unkown
page read and write
400000
unkown
page readonly
2BFF000
stack
page read and write
478000
unkown
page readonly
19D000
stack
page read and write
680000
heap
page read and write
474000
unkown
page read and write
220E000
stack
page read and write
5B1000
heap
page read and write
5E8000
heap
page read and write
401000
unkown
page execute read
471000
unkown
page read and write
729000
heap
page read and write
19D000
stack
page read and write
24BE000
stack
page read and write
675000
heap
page read and write
56A000
heap
page read and write
4CE000
stack
page read and write
30EF000
stack
page read and write
520000
heap
page read and write
20D0000
heap
page read and write
26FE000
stack
page read and write
560000
heap
page read and write
91E000
stack
page read and write
474000
unkown
page read and write
1F0000
heap
page read and write
478000
unkown
page readonly
5E0000
heap
page read and write
271F000
stack
page read and write
2C3C000
stack
page read and write
5D3000
heap
page read and write
1F0000
heap
page read and write
478000
unkown
page readonly
401000
unkown
page execute read
9B000
stack
page read and write
400000
unkown
page readonly
91F000
stack
page read and write
5AE000
stack
page read and write
8BF000
stack
page read and write
20F0000
heap
page read and write
71E000
stack
page read and write
6AE000
stack
page read and write
297F000
stack
page read and write
6E0000
heap
page read and write
478000
unkown
page readonly
401000
unkown
page execute read
400000
unkown
page readonly
471000
unkown
page write copy
478000
unkown
page readonly
1F0000
heap
page read and write
401000
unkown
page execute read
1FB0000
heap
page read and write
25C0000
heap
page read and write
6B0000
heap
page read and write
471000
unkown
page write copy
478000
unkown
page readonly
9C000
stack
page read and write
9C000
stack
page read and write
81E000
stack
page read and write
471000
unkown
page read and write
471000
unkown
page read and write
670000
heap
page read and write
640000
heap
page read and write
471000
unkown
page write copy
19C000
stack
page read and write
401000
unkown
page execute read
401000
unkown
page execute read
261E000
stack
page read and write
2AFE000
stack
page read and write
7BE000
stack
page read and write
471000
unkown
page write copy
20F0000
heap
page read and write
19D000
stack
page read and write
6DE000
stack
page read and write
9C000
stack
page read and write
471000
unkown
page write copy
474000
unkown
page read and write
2210000
heap
page read and write
247F000
stack
page read and write
560000
heap
page read and write
400000
unkown
page readonly
81E000
stack
page read and write
474000
unkown
page read and write
20C0000
heap
page read and write
5A0000
heap
page read and write
283F000
stack
page read and write
660000
heap
page read and write
5E2000
heap
page read and write
5E8000
heap
page read and write
5DA000
heap
page read and write
401000
unkown
page execute read
400000
unkown
page readonly
5C1000
heap
page read and write
75A000
heap
page read and write
690000
heap
page read and write
560000
heap
page read and write
5D0000
heap
page read and write
2D3C000
stack
page read and write
478000
unkown
page readonly
400000
unkown
page readonly
5D3000
heap
page read and write
233F000
stack
page read and write
401000
unkown
page execute read
273E000
stack
page read and write
5D5000
heap
page read and write
59E000
stack
page read and write
29BE000
stack
page read and write
400000
unkown
page readonly
287E000
stack
page read and write
400000
unkown
page readonly
223C000
stack
page read and write
19B000
stack
page read and write
478000
unkown
page readonly
5E0000
heap
page read and write
77A000
heap
page read and write
510000
heap
page read and write
20EE000
stack
page read and write
471000
unkown
page read and write
474000
unkown
page read and write
50E000
stack
page read and write
720000
heap
page read and write
2FEE000
stack
page read and write
400000
unkown
page readonly
401000
unkown
page execute read
5E8000
heap
page read and write
1F0000
heap
page read and write
780000
heap
page read and write
2ABF000
stack
page read and write
2160000
heap
page read and write
9C000
stack
page read and write
400000
unkown
page readonly
478000
unkown
page readonly
5B0000
heap
page read and write
25BF000
stack
page read and write
401000
unkown
page execute read
237C000
stack
page read and write
91E000
stack
page read and write
478000
unkown
page readonly
5E7000
heap
page read and write
1F0000
heap
page read and write
There are 148 hidden memdumps, click here to show them.