IOC Report
1728239645797292025226e9acb49e89d83573a2cc0d27d167f28d4f30183138d9571f4d7c739.dat-decoded.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\1728239645797292025226e9acb49e89d83573a2cc0d27d167f28d4f30183138d9571f4d7c739.dat-decoded.exe
"C:\Users\user\Desktop\1728239645797292025226e9acb49e89d83573a2cc0d27d167f28d4f30183138d9571f4d7c739.dat-decoded.exe"
malicious

URLs

Name
IP
Malicious
michelsrmccontrol.duckdns.org
malicious
http://geoplugin.net/json.gp
unknown
http://geoplugin.net/json.gp/C
unknown

Domains

Name
IP
Malicious
michelsrmccontrol.duckdns.org
107.175.130.20
malicious

IPs

IP
Domain
Country
Malicious
107.175.130.20
michelsrmccontrol.duckdns.org
United States
malicious

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\SOFTWARE\Rmc-PXKO50
exepath
malicious
HKEY_CURRENT_USER\SOFTWARE\Rmc-PXKO50
licence
malicious
HKEY_CURRENT_USER\SOFTWARE\Rmc-PXKO50
time
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
459000
unkown
page readonly
malicious
459000
unkown
page readonly
malicious
76E000
heap
page read and write
malicious
2240000
heap
page read and write
580000
heap
page read and write
560000
heap
page read and write
471000
unkown
page read and write
793000
heap
page read and write
9C000
stack
page read and write
21FF000
stack
page read and write
474000
unkown
page read and write
74E000
stack
page read and write
400000
unkown
page readonly
478000
unkown
page readonly
860000
heap
page read and write
5CE000
stack
page read and write
1F0000
heap
page read and write
19C000
stack
page read and write
400000
unkown
page readonly
587000
heap
page read and write
234F000
unkown
page read and write
76A000
heap
page read and write
6CF000
stack
page read and write
478000
unkown
page readonly
401000
unkown
page execute read
401000
unkown
page execute read
471000
unkown
page write copy
70E000
stack
page read and write
760000
heap
page read and write
2200000
heap
page read and write
There are 20 hidden memdumps, click here to show them.