IOC Report
file.exe

loading gif

Files

File Path
Type
Category
Malicious
file.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows Driver Server.exe
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows Driver Server.exe:Zone.Identifier
ASCII text, with CRLF line terminators
modified
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\BEDT2L3A\json[1].json
JSON data
dropped
C:\Users\user\AppData\Roaming\Microsoft\_temp.dat
data
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\file.exe
"C:\Users\user\Desktop\file.exe"
malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows Driver Server.exe
"C:\Users\user\AppData\Roaming\Microsoft\Windows Driver Server.exe"
malicious
C:\Windows\SysWOW64\svchost.exe
svchost.exe
malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows Driver Server.exe
"C:\Users\user\AppData\Roaming\Microsoft\Windows Driver Server.exe"
malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows Driver Server.exe
"C:\Users\user\AppData\Roaming\Microsoft\Windows Driver Server.exe"
malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows Driver Server.exe
"C:\Users\user\AppData\Roaming\Microsoft\Windows Driver Server.exe"
malicious

URLs

Name
IP
Malicious
5.20.120.177
malicious
http://geoplugin.net/json.gp
178.237.33.50
http://geoplugin.net/json.gpv
unknown
http://geoplugin.net/json.gp5
unknown
http://geoplugin.net/json.gp/C
unknown
http://geoplugin.net/json.gpl
unknown
http://geoplugin.net/json.gpSystem32
unknown

Domains

Name
IP
Malicious
geoplugin.net
178.237.33.50

IPs

IP
Domain
Country
Malicious
5.20.120.177
unknown
Lithuania
malicious
178.237.33.50
geoplugin.net
Netherlands

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Rmc-HWAIZA
malicious
HKEY_CURRENT_USER\SOFTWARE\Rmc-HWAIZA
del
malicious
HKEY_CURRENT_USER\SOFTWARE\Rmc-HWAIZA
exepath
malicious
HKEY_CURRENT_USER\SOFTWARE\Rmc-HWAIZA
licence
malicious
HKEY_CURRENT_USER\SOFTWARE\Rmc-HWAIZA
WD
malicious
HKEY_CURRENT_USER\SOFTWARE\Rmc-HWAIZA
time
malicious
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run
Rmc-HWAIZA

Memdumps

Base Address
Regiontype
Protect
Malicious
29A0000
unclassified section
page execute and read and write
malicious
459000
unkown
page readonly
malicious
459000
unkown
page readonly
malicious
459000
unkown
page readonly
malicious
459000
unkown
page readonly
malicious
650000
system
page execute and read and write
malicious
459000
unkown
page readonly
malicious
2A29000
heap
page read and write
malicious
459000
unkown
page readonly
malicious
6A1000
heap
page read and write
malicious
53E000
heap
page read and write
malicious
459000
unkown
page readonly
malicious
459000
unkown
page readonly
malicious
459000
unkown
page readonly
malicious
459000
unkown
page readonly
malicious
50E000
stack
page read and write
400000
unkown
page readonly
5F7000
heap
page read and write
401000
unkown
page execute read
480000
heap
page read and write
4BE000
stack
page read and write
19A000
stack
page read and write
540000
heap
page read and write
58E000
stack
page read and write
5E7000
heap
page read and write
401000
unkown
page execute read
2ACF000
stack
page read and write
670000
heap
page read and write
2A5E000
stack
page read and write
4C0000
heap
page read and write
5DE000
stack
page read and write
6F0000
heap
page read and write
630000
heap
page read and write
53A000
heap
page read and write
712000
heap
page read and write
471000
unkown
page write copy
25DF000
stack
page read and write
1F0000
heap
page read and write
474000
unkown
page read and write
58E000
stack
page read and write
22B0000
heap
page read and write
2C4E000
stack
page read and write
5CE000
stack
page read and write
235F000
stack
page read and write
747000
heap
page read and write
478000
unkown
page readonly
471000
unkown
page write copy
7E8000
heap
page read and write
9DE000
stack
page read and write
471000
unkown
page write copy
478000
unkown
page readonly
471000
unkown
page read and write
4C0000
heap
page read and write
401000
unkown
page execute read
6AB000
heap
page read and write
9B000
stack
page read and write
9C000
stack
page read and write
474000
unkown
page read and write
401000
unkown
page execute read
400000
unkown
page readonly
474000
unkown
page read and write
478000
unkown
page readonly
63C000
stack
page read and write
615000
heap
page read and write
22C0000
heap
page read and write
6FF000
heap
page read and write
270E000
stack
page read and write
400000
unkown
page readonly
7FF000
stack
page read and write
4B0000
heap
page read and write
478000
unkown
page readonly
7E0000
heap
page read and write
3910000
heap
page read and write
271F000
stack
page read and write
2A18000
unclassified section
page execute and read and write
2D4F000
stack
page read and write
2FF0000
heap
page read and write
5D0000
heap
page read and write
93F000
stack
page read and write
478000
unkown
page readonly
86E000
stack
page read and write
748000
heap
page read and write
471000
unkown
page write copy
400000
unkown
page readonly
6C8000
system
page execute and read and write
96F000
stack
page read and write
1F0000
heap
page read and write
6D0000
heap
page read and write
471000
unkown
page read and write
2B5F000
stack
page read and write
9C000
stack
page read and write
401000
unkown
page execute read
400000
unkown
page readonly
50F000
stack
page read and write
62E000
heap
page read and write
289E000
stack
page read and write
285E000
stack
page read and write
474000
unkown
page read and write
2B0E000
stack
page read and write
261E000
stack
page read and write
249F000
stack
page read and write
19D000
stack
page read and write
228E000
stack
page read and write
4C7000
heap
page read and write
600000
heap
page read and write
478000
unkown
page readonly
790000
heap
page read and write
71E000
stack
page read and write
2802000
heap
page read and write
720000
heap
page read and write
2FE0000
heap
page read and write
67E000
heap
page read and write
740000
heap
page read and write
27C0000
heap
page read and write
530000
heap
page read and write
478000
unkown
page readonly
5D0000
heap
page read and write
620000
heap
page read and write
61E000
stack
page read and write
278E000
stack
page read and write
9C000
stack
page read and write
471000
unkown
page write copy
6D5000
heap
page read and write
1F0000
heap
page read and write
3DC000
stack
page read and write
478000
unkown
page readonly
9C000
stack
page read and write
6FE000
heap
page read and write
401000
unkown
page execute read
625000
heap
page read and write
474000
unkown
page read and write
400000
unkown
page readonly
2D8C000
stack
page read and write
2A24000
heap
page read and write
2A12000
heap
page read and write
225E000
stack
page read and write
615000
heap
page read and write
19D000
stack
page read and write
401000
unkown
page execute read
239C000
stack
page read and write
62E000
heap
page read and write
400000
unkown
page readonly
3A20000
heap
page read and write
471000
unkown
page read and write
4C5000
heap
page read and write
2A14000
unclassified section
page execute and read and write
2E8C000
stack
page read and write
400000
unkown
page readonly
2290000
heap
page read and write
400000
unkown
page readonly
471000
unkown
page read and write
478000
unkown
page readonly
730000
heap
page readonly
70E000
stack
page read and write
2150000
heap
page read and write
19D000
stack
page read and write
2A00000
heap
page read and write
712000
heap
page read and write
19D000
stack
page read and write
61E000
stack
page read and write
1F0000
heap
page read and write
401000
unkown
page execute read
22C7000
heap
page read and write
471000
unkown
page read and write
351F000
stack
page read and write
2370000
heap
page read and write
4C0000
heap
page read and write
401000
unkown
page execute read
67A000
heap
page read and write
2B01000
heap
page read and write
400000
unkown
page readonly
401000
unkown
page execute read
6C4000
system
page execute and read and write
480000
heap
page read and write
740000
heap
page read and write
ADF000
stack
page read and write
275D000
stack
page read and write
299F000
stack
page read and write
5F7000
heap
page read and write
24DC000
stack
page read and write
2FDE000
stack
page read and write
93F000
stack
page read and write
2C0F000
stack
page read and write
1F0000
heap
page read and write
478000
unkown
page readonly
73E000
stack
page read and write
5CE000
stack
page read and write
28E0000
heap
page read and write
626000
heap
page read and write
274E000
stack
page read and write
28CF000
stack
page read and write
62E000
heap
page read and write
28D0000
heap
page read and write
There are 183 hidden memdumps, click here to show them.