IOC Report
17273431863ab7a79d0c4618c39383a44188eff7849fa1201010774aef83d8c896a4db4eb8287.dat-decoded.exe

loading gif

Files

File Path
Type
Category
Malicious
17273431863ab7a79d0c4618c39383a44188eff7849fa1201010774aef83d8c896a4db4eb8287.dat-decoded.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\ProgramData\remcos\logs.dat
data
dropped
malicious

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\17273431863ab7a79d0c4618c39383a44188eff7849fa1201010774aef83d8c896a4db4eb8287.dat-decoded.exe
"C:\Users\user\Desktop\17273431863ab7a79d0c4618c39383a44188eff7849fa1201010774aef83d8c896a4db4eb8287.dat-decoded.exe"
malicious

URLs

Name
IP
Malicious
23spt.duckdns.org
malicious
http://geoplugin.net/json.gp
unknown
http://geoplugin.net/json.gp/C
unknown

Domains

Name
IP
Malicious
23spt.duckdns.org
181.236.206.3
malicious

IPs

IP
Domain
Country
Malicious
191.93.114.27
unknown
Colombia
malicious
181.236.206.3
23spt.duckdns.org
Colombia
malicious

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\SOFTWARE\Rmc-RZH5WZ
exepath
HKEY_CURRENT_USER\SOFTWARE\Rmc-RZH5WZ
licence
HKEY_CURRENT_USER\SOFTWARE\Rmc-RZH5WZ
time

Memdumps

Base Address
Regiontype
Protect
Malicious
459000
unkown
page readonly
malicious
459000
unkown
page readonly
malicious
78E000
heap
page read and write
malicious
22FF000
stack
page read and write
malicious
400000
unkown
page readonly
74E000
stack
page read and write
471000
unkown
page read and write
8BE000
stack
page read and write
560000
heap
page read and write
215C000
stack
page read and write
750000
heap
page read and write
478000
unkown
page readonly
25FF000
stack
page read and write
6FF000
stack
page read and write
5F6000
heap
page read and write
9C000
stack
page read and write
24FF000
stack
page read and write
2740000
heap
page read and write
478000
unkown
page readonly
5F0000
heap
page read and write
401000
unkown
page execute read
19C000
stack
page read and write
78A000
heap
page read and write
401000
unkown
page execute read
293F000
stack
page read and write
474000
unkown
page read and write
2750000
heap
page read and write
21DE000
stack
page read and write
5BE000
stack
page read and write
219C000
stack
page read and write
1F0000
heap
page read and write
780000
heap
page read and write
21F0000
heap
page read and write
471000
unkown
page write copy
400000
unkown
page readonly
23FF000
stack
page read and write
There are 26 hidden memdumps, click here to show them.