IOC Report
1728033125dd387fed0490e7ade394383eca6a3c5cb1fd0e94f8067e03fabd8e0d741cea5c331.dat-decoded.exe

loading gif

Files

File Path
Type
Category
Malicious
1728033125dd387fed0490e7ade394383eca6a3c5cb1fd0e94f8067e03fabd8e0d741cea5c331.dat-decoded.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\ProgramData\remcos\logs.dat
data
dropped
malicious

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\1728033125dd387fed0490e7ade394383eca6a3c5cb1fd0e94f8067e03fabd8e0d741cea5c331.dat-decoded.exe
"C:\Users\user\Desktop\1728033125dd387fed0490e7ade394383eca6a3c5cb1fd0e94f8067e03fabd8e0d741cea5c331.dat-decoded.exe"
malicious

URLs

Name
IP
Malicious
ab9001.ddns.net
malicious
http://geoplugin.net/json.gp
unknown
http://geoplugin.net/json.gp/C
unknown

Domains

Name
IP
Malicious
ab9001.ddns.net
64.188.16.157
malicious
s-part-0032.t-0009.t-msedge.net
13.107.246.60

IPs

IP
Domain
Country
Malicious
64.188.16.157
ab9001.ddns.net
United States
malicious

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\SOFTWARE\Chrorne-CKQJ2Y
exepath
HKEY_CURRENT_USER\SOFTWARE\Chrorne-CKQJ2Y
licence

Memdumps

Base Address
Regiontype
Protect
Malicious
4AE000
heap
page read and write
malicious
456000
unkown
page readonly
malicious
456000
unkown
page readonly
malicious
227F000
stack
page read and write
malicious
401000
unkown
page execute read
680000
heap
page read and write
4A0000
heap
page read and write
2170000
heap
page read and write
20DE000
stack
page read and write
211C000
stack
page read and write
25BF000
stack
page read and write
471000
unkown
page read and write
475000
unkown
page readonly
480000
heap
page read and write
400000
unkown
page readonly
9C000
stack
page read and write
475000
unkown
page readonly
1C0000
heap
page read and write
25C0000
heap
page read and write
215C000
stack
page read and write
8EE000
stack
page read and write
237F000
stack
page read and write
670000
heap
page read and write
8AF000
stack
page read and write
24BE000
stack
page read and write
400000
unkown
page readonly
19C000
stack
page read and write
1C6000
heap
page read and write
401000
unkown
page execute read
46E000
unkown
page read and write
46E000
unkown
page write copy
4AA000
heap
page read and write
490000
heap
page read and write
4E1000
heap
page read and write
26DF000
unkown
page read and write
7AE000
stack
page read and write
247F000
stack
page read and write
There are 27 hidden memdumps, click here to show them.