IOC Report
1728239644b6c097b50f50c5ed70baa52a8cacbfdc1e82b38c0aa5c471e1a07dbef595bc59540.dat-decoded.exe

loading gif

Files

File Path
Type
Category
Malicious
1728239644b6c097b50f50c5ed70baa52a8cacbfdc1e82b38c0aa5c471e1a07dbef595bc59540.dat-decoded.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\BEDT2L3A\json[1].json
JSON data
dropped
C:\Users\user\AppData\Local\Temp\bhvD06.tmp
Extensible storage engine DataBase, version 0x620, checksum 0xe41c9139, page size 32768, DirtyShutdown, Windows version 10.0
dropped
C:\Users\user\AppData\Local\Temp\xttxrevmuropxyhmme
Unicode text, UTF-16, little-endian text, with no line terminators
modified

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\1728239644b6c097b50f50c5ed70baa52a8cacbfdc1e82b38c0aa5c471e1a07dbef595bc59540.dat-decoded.exe
"C:\Users\user\Desktop\1728239644b6c097b50f50c5ed70baa52a8cacbfdc1e82b38c0aa5c471e1a07dbef595bc59540.dat-decoded.exe"
malicious
C:\Users\user\Desktop\1728239644b6c097b50f50c5ed70baa52a8cacbfdc1e82b38c0aa5c471e1a07dbef595bc59540.dat-decoded.exe
C:\Users\user\Desktop\1728239644b6c097b50f50c5ed70baa52a8cacbfdc1e82b38c0aa5c471e1a07dbef595bc59540.dat-decoded.exe /stext "C:\Users\user\AppData\Local\Temp\xttxrevmuropxyhmme"
malicious
C:\Users\user\Desktop\1728239644b6c097b50f50c5ed70baa52a8cacbfdc1e82b38c0aa5c471e1a07dbef595bc59540.dat-decoded.exe
C:\Users\user\Desktop\1728239644b6c097b50f50c5ed70baa52a8cacbfdc1e82b38c0aa5c471e1a07dbef595bc59540.dat-decoded.exe /stext "C:\Users\user\AppData\Local\Temp\hnyqswgoizgciedqvprkl"
malicious
C:\Users\user\Desktop\1728239644b6c097b50f50c5ed70baa52a8cacbfdc1e82b38c0aa5c471e1a07dbef595bc59540.dat-decoded.exe
C:\Users\user\Desktop\1728239644b6c097b50f50c5ed70baa52a8cacbfdc1e82b38c0aa5c471e1a07dbef595bc59540.dat-decoded.exe /stext "C:\Users\user\AppData\Local\Temp\jpebsprhwhyhkkrunalmokuw"
malicious

URLs

Name
IP
Malicious
cavps7.duckdns.org
malicious
https://M365CDN.nel.measure.office.net/api/report?FrontEnd=VerizonCDNWorldWide&DestinationEndpoint=P
unknown
https://www.office.com/
unknown
http://geoplugin.net/json.gp:U
unknown
https://fp-afd.azurefd.us/apc/trans.gif?a2555e10569a45fe03b885d268c50da9
unknown
http://www.imvu.comr
unknown
http://geoplugin.net/json.gpl
unknown
https://aefd.nelreports.net/api/report?cat=bingth
unknown
http://www.imvu.com
unknown
https://aefd.nelreports.net/api/report?cat=wsb
unknown
http://www.imvu.comppData
unknown
http://www.nirsoft.net
unknown
https://aefd.nelreports.net/api/report?cat=bingaotak
unknown
https://assets.msn.com/weathermapdata/1/static/weather/Icons/JyNGQgA=/Condition/AAehwh2.svg
unknown
https://deff.nelreports.net/api/report?cat=msn
unknown
https://ecfdb90f321c52ef6e93077f63413543.azr.footprintdns.com/apc/trans.gif?c2fcd52267835a3e34f9ac05
unknown
https://ecfdb90f321c52ef6e93077f63413543.azr.footprintdns.com/apc/trans.gif?bd78002c55888096ce060c58
unknown
http://www.imvu.comhttp://www.ebuddy.comhttps://www.google.com
unknown
http://geoplugin.net/json.gp3U
unknown
http://geoplugin.net/json.gp
178.237.33.50
https://www.google.com
unknown
https://aefd.nelreports.net/api/report?cat=bingaot
unknown
https://fp-afd.azurefd.us/apc/trans.gif?69c749c200c753dfb00f5bc8299ab8eb
unknown
http://geoplugin.net/json.gp/C
unknown
https://cxcs.microsoft.net/api/settings/en-GB/xml/settings-tipset?release=20h1&sku=Professional&plat
unknown
https://aefd.nelreports.net/api/report?cat=bingrms
unknown
https://www.google.com/accounts/servicelogin
unknown
https://login.yahoo.com/config/login
unknown
http://www.nirsoft.net/
unknown
https://ecs.nel.measure.office.net?TenantId=ODSP_Sync_Client&DestinationEndpoint=Edge-Prod-LAX31r5c&
unknown
http://www.ebuddy.com
unknown
There are 21 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
cavps7.duckdns.org
84.32.44.139
malicious
geoplugin.net
178.237.33.50

IPs

IP
Domain
Country
Malicious
84.32.44.139
cavps7.duckdns.org
Lithuania
malicious
178.237.33.50
geoplugin.net
Netherlands

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\SOFTWARE\Rmc-43JG4A
exepath
malicious
HKEY_CURRENT_USER\SOFTWARE\Rmc-43JG4A
licence
malicious
HKEY_CURRENT_USER\SOFTWARE\Rmc-43JG4A
time
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
459000
unkown
page readonly
malicious
459000
unkown
page readonly
malicious
4BE000
heap
page read and write
malicious
459000
unkown
page readonly
malicious
459000
unkown
page readonly
malicious
459000
unkown
page readonly
malicious
400000
system
page execute and read and write
2169000
heap
page read and write
555000
heap
page read and write
536000
heap
page read and write
218A000
heap
page read and write
2178000
heap
page read and write
4FE000
heap
page read and write
990000
heap
page read and write
2175000
heap
page read and write
554000
heap
page read and write
2876000
heap
page read and write
216E000
heap
page read and write
216D000
heap
page read and write
529000
heap
page read and write
555000
heap
page read and write
529000
heap
page read and write
2861000
heap
page read and write
2861000
heap
page read and write
2A40000
trusted library allocation
page read and write
284C000
heap
page read and write
59F000
heap
page read and write
236F000
stack
page read and write
2178000
heap
page read and write
598000
heap
page read and write
540000
heap
page read and write
595000
heap
page read and write
285F000
heap
page read and write
28A6000
heap
page read and write
940000
trusted library allocation
page read and write
478000
unkown
page readonly
2DDC000
heap
page read and write
459000
system
page execute and read and write
2160000
heap
page read and write
59F000
heap
page read and write
216E000
heap
page read and write
2841000
heap
page read and write
54F000
heap
page read and write
546000
heap
page read and write
549000
heap
page read and write
284C000
heap
page read and write
490000
heap
page read and write
595000
heap
page read and write
4A0000
heap
page read and write
2210000
heap
page read and write
478000
unkown
page readonly
547000
heap
page read and write
2DA0000
heap
page read and write
2A40000
trusted library allocation
page read and write
28A6000
heap
page read and write
1F0000
heap
page read and write
2847000
heap
page read and write
216D000
heap
page read and write
3483000
heap
page read and write
2849000
heap
page read and write
540000
heap
page read and write
284A000
heap
page read and write
2840000
heap
page read and write
401000
unkown
page execute read
54C000
heap
page read and write
4A4000
heap
page read and write
52B000
heap
page read and write
546000
heap
page read and write
54F000
heap
page read and write
3A40000
unclassified section
page execute and read and write
471000
unkown
page write copy
400000
unkown
page readonly
56F000
heap
page read and write
284A000
heap
page read and write
2A40000
trusted library allocation
page read and write
284C000
heap
page read and write
2175000
heap
page read and write
2198000
heap
page read and write
566000
heap
page read and write
2169000
heap
page read and write
546000
heap
page read and write
2170000
heap
page read and write
53B000
heap
page read and write
59F000
heap
page read and write
555000
heap
page read and write
690000
heap
page read and write
2DD6000
heap
page read and write
3A99000
unclassified section
page execute and read and write
2848000
heap
page read and write
400000
unkown
page readonly
28A6000
heap
page read and write
2D98000
heap
page read and write
531000
heap
page read and write
28A6000
heap
page read and write
2848000
heap
page read and write
4A4000
heap
page read and write
2848000
heap
page read and write
2848000
heap
page read and write
594000
heap
page read and write
595000
heap
page read and write
28A6000
heap
page read and write
691000
heap
page read and write
3A9D000
unclassified section
page execute and read and write
511000
heap
page read and write
540000
heap
page read and write
226E000
stack
page read and write
2178000
heap
page read and write
4BA000
heap
page read and write
284A000
heap
page read and write
2D98000
heap
page read and write
34FC000
heap
page read and write
2175000
heap
page read and write
93F000
stack
page read and write
28A6000
heap
page read and write
52A000
heap
page read and write
53B000
heap
page read and write
51D000
heap
page read and write
594000
heap
page read and write
59F000
heap
page read and write
2581000
heap
page read and write
2161000
heap
page read and write
19C000
stack
page read and write
53A000
heap
page read and write
99D000
heap
page read and write
1F0000
heap
page read and write
2847000
heap
page read and write
550000
heap
page read and write
2160000
heap
page read and write
9C000
stack
page read and write
2A40000
trusted library allocation
page read and write
554000
heap
page read and write
4A4000
heap
page read and write
566000
heap
page read and write
2FFE000
stack
page read and write
2176000
heap
page read and write
2178000
heap
page read and write
193000
stack
page read and write
21B9000
heap
page read and write
4A4000
heap
page read and write
3B26000
unclassified section
page execute and read and write
474000
unkown
page read and write
45C000
system
page execute and read and write
99B000
heap
page read and write
595000
heap
page read and write
2887000
heap
page read and write
1C0000
heap
page read and write
20EE000
stack
page read and write
5A4000
heap
page read and write
2161000
heap
page read and write
34FB000
heap
page read and write
59E000
stack
page read and write
69F000
stack
page read and write
3391000
heap
page read and write
2851000
heap
page read and write
2171000
heap
page read and write
28A6000
heap
page read and write
2175000
heap
page read and write
89C000
heap
page read and write
2171000
heap
page read and write
2866000
heap
page read and write
2866000
heap
page read and write
9C000
stack
page read and write
2747000
heap
page read and write
30FF000
stack
page read and write
9C000
stack
page read and write
4A4000
heap
page read and write
28A6000
heap
page read and write
2849000
heap
page read and write
2D9A000
heap
page read and write
471000
unkown
page write copy
473000
system
page execute and read and write
3409000
heap
page read and write
257F000
stack
page read and write
2861000
heap
page read and write
52A000
heap
page read and write
2866000
heap
page read and write
52B000
heap
page read and write
556000
heap
page read and write
471000
unkown
page read and write
555000
heap
page read and write
2181000
heap
page read and write
2DD6000
heap
page read and write
28A6000
heap
page read and write
28A6000
heap
page read and write
566000
heap
page read and write
3B50000
unclassified section
page execute and read and write
565000
heap
page read and write
21A3000
heap
page read and write
284A000
heap
page read and write
218E000
heap
page read and write
554000
heap
page read and write
59F000
heap
page read and write
510000
heap
page read and write
2851000
heap
page read and write
554000
heap
page read and write
2862000
heap
page read and write
478000
unkown
page readonly
554000
heap
page read and write
10016000
direct allocation
page execute and read and write
2160000
heap
page read and write
4A4000
heap
page read and write
2841000
heap
page read and write
555000
heap
page read and write
6EE000
stack
page read and write
546000
heap
page read and write
4A4000
heap
page read and write
546000
heap
page read and write
2841000
heap
page read and write
2120000
heap
page read and write
2A40000
trusted library allocation
page read and write
2176000
heap
page read and write
549000
heap
page read and write
28A6000
heap
page read and write
529000
heap
page read and write
554000
heap
page read and write
2175000
heap
page read and write
216E000
heap
page read and write
3AB3000
unclassified section
page execute and read and write
400000
unkown
page readonly
3390000
heap
page read and write
1F0000
heap
page read and write
216E000
heap
page read and write
99E000
heap
page read and write
2DB4000
heap
page read and write
2D9A000
heap
page read and write
554000
heap
page read and write
2861000
heap
page read and write
52D000
heap
page read and write
566000
heap
page read and write
566000
heap
page read and write
5A1000
heap
page read and write
587000
heap
page read and write
4A4000
heap
page read and write
52D000
heap
page read and write
28A6000
heap
page read and write
555000
heap
page read and write
548000
heap
page read and write
359D000
heap
page read and write
556000
heap
page read and write
59F000
heap
page read and write
28A6000
heap
page read and write
2DD3000
heap
page read and write
53B000
heap
page read and write
2D9A000
heap
page read and write
216E000
heap
page read and write
400000
system
page execute and read and write
216E000
heap
page read and write
59B000
heap
page read and write
2178000
heap
page read and write
554000
heap
page read and write
19C000
stack
page read and write
2843000
heap
page read and write
284C000
heap
page read and write
28A6000
heap
page read and write
533000
heap
page read and write
470000
heap
page read and write
7BE000
stack
page read and write
5DE000
stack
page read and write
2161000
heap
page read and write
2160000
heap
page read and write
2169000
heap
page read and write
549000
heap
page read and write
4A4000
heap
page read and write
690000
heap
page read and write
470000
heap
page read and write
28A6000
heap
page read and write
598000
heap
page read and write
536000
heap
page read and write
2860000
heap
page read and write
536000
heap
page read and write
59F000
heap
page read and write
52A000
heap
page read and write
2197000
heap
page read and write
4EF000
heap
page read and write
2169000
heap
page read and write
59F000
heap
page read and write
59F000
heap
page read and write
2741000
heap
page read and write
2A40000
trusted library allocation
page read and write
554000
heap
page read and write
660000
heap
page read and write
28A6000
heap
page read and write
680000
heap
page read and write
2310000
heap
page read and write
2165000
heap
page read and write
478000
unkown
page readonly
2847000
heap
page read and write
2161000
heap
page read and write
554000
heap
page read and write
222F000
stack
page read and write
748000
heap
page read and write
2847000
heap
page read and write
2861000
heap
page read and write
2848000
heap
page read and write
99D000
heap
page read and write
587000
heap
page read and write
216D000
heap
page read and write
554000
heap
page read and write
2176000
heap
page read and write
401000
unkown
page execute read
2DD6000
heap
page read and write
2161000
heap
page read and write
1C6000
heap
page read and write
2741000
heap
page read and write
2887000
heap
page read and write
2581000
heap
page read and write
2849000
heap
page read and write
595000
heap
page read and write
2D20000
heap
page read and write
355C000
heap
page read and write
51D000
heap
page read and write
566000
heap
page read and write
471000
unkown
page write copy
2860000
heap
page read and write
46E000
stack
page read and write
3391000
heap
page read and write
28A6000
heap
page read and write
5A1000
heap
page read and write
2841000
heap
page read and write
284C000
heap
page read and write
5A1000
heap
page read and write
7BF000
stack
page read and write
4FE000
heap
page read and write
569000
heap
page read and write
890000
heap
page read and write
540000
heap
page read and write
2178000
heap
page read and write
28A6000
heap
page read and write
542000
heap
page read and write
4A0000
heap
page read and write
2DB1000
heap
page read and write
740000
heap
page read and write
2891000
heap
page read and write
990000
heap
page read and write
59F000
heap
page read and write
28A6000
heap
page read and write
554000
heap
page read and write
401000
unkown
page execute read
2DD6000
heap
page read and write
85F000
stack
page read and write
6A0000
heap
page read and write
2140000
heap
page read and write
41B000
system
page execute and read and write
582000
heap
page read and write
284C000
heap
page read and write
3B2C000
unclassified section
page execute and read and write
668000
heap
page read and write
401000
unkown
page execute read
284A000
heap
page read and write
284C000
heap
page read and write
89C000
heap
page read and write
400000
unkown
page readonly
99B000
heap
page read and write
52D000
heap
page read and write
566000
heap
page read and write
536000
heap
page read and write
56F000
heap
page read and write
3391000
heap
page read and write
2178000
heap
page read and write
554000
heap
page read and write
216E000
heap
page read and write
2160000
heap
page read and write
4A4000
heap
page read and write
2178000
heap
page read and write
710000
heap
page read and write
555000
heap
page read and write
456000
system
page execute and read and write
52A000
heap
page read and write
478000
unkown
page readonly
569000
heap
page read and write
471000
unkown
page write copy
51D000
heap
page read and write
2D21000
heap
page read and write
177000
stack
page read and write
51D000
heap
page read and write
587000
heap
page read and write
2D98000
heap
page read and write
10000000
direct allocation
page read and write
45D000
system
page execute and read and write
217A000
heap
page read and write
533000
heap
page read and write
4B0000
heap
page read and write
2580000
heap
page read and write
217A000
heap
page read and write
566000
heap
page read and write
2165000
heap
page read and write
690000
heap
page read and write
555000
heap
page read and write
3B6B000
unclassified section
page execute and read and write
2161000
heap
page read and write
28A6000
heap
page read and write
10001000
direct allocation
page execute and read and write
2847000
heap
page read and write
28A6000
heap
page read and write
2169000
heap
page read and write
52E000
heap
page read and write
2861000
heap
page read and write
2841000
heap
page read and write
2169000
heap
page read and write
287A000
heap
page read and write
284A000
heap
page read and write
2100000
heap
page read and write
4A4000
heap
page read and write
996000
heap
page read and write
4A4000
heap
page read and write
9C000
stack
page read and write
4A4000
heap
page read and write
2178000
heap
page read and write
28A6000
heap
page read and write
52D000
heap
page read and write
400000
system
page execute and read and write
540000
heap
page read and write
559000
heap
page read and write
550000
heap
page read and write
54C000
heap
page read and write
2DBA000
heap
page read and write
999000
heap
page read and write
555000
heap
page read and write
28A6000
heap
page read and write
3631000
heap
page read and write
284A000
heap
page read and write
549000
heap
page read and write
588000
heap
page read and write
993000
heap
page read and write
99A000
heap
page read and write
2178000
heap
page read and write
28A6000
heap
page read and write
2171000
heap
page read and write
2178000
heap
page read and write
2176000
heap
page read and write
2849000
heap
page read and write
401000
unkown
page execute read
284A000
heap
page read and write
28A6000
heap
page read and write
59B000
heap
page read and write
2178000
heap
page read and write
28A6000
heap
page read and write
56D000
heap
page read and write
3630000
heap
page read and write
21B8000
heap
page read and write
2740000
heap
page read and write
2859000
heap
page read and write
4A4000
heap
page read and write
893000
heap
page read and write
2741000
heap
page read and write
352B000
heap
page read and write
99A000
heap
page read and write
595000
heap
page read and write
7FE000
stack
page read and write
220F000
stack
page read and write
2859000
heap
page read and write
6BE000
stack
page read and write
52D000
heap
page read and write
2178000
heap
page read and write
28A6000
heap
page read and write
216D000
heap
page read and write
19A000
stack
page read and write
960000
heap
page read and write
2178000
heap
page read and write
59B000
heap
page read and write
53B000
heap
page read and write
2866000
heap
page read and write
2D21000
heap
page read and write
2DC2000
heap
page read and write
18F000
stack
page read and write
2161000
heap
page read and write
216E000
heap
page read and write
3AD0000
unclassified section
page execute and read and write
868000
heap
page read and write
554000
heap
page read and write
554000
heap
page read and write
17C000
stack
page read and write
2178000
heap
page read and write
2161000
heap
page read and write
4A4000
heap
page read and write
284E000
heap
page read and write
554000
heap
page read and write
400000
unkown
page readonly
C5F000
stack
page read and write
555000
heap
page read and write
566000
heap
page read and write
598000
heap
page read and write
2861000
heap
page read and write
4A4000
heap
page read and write
595000
heap
page read and write
940000
trusted library allocation
page read and write
4FE000
heap
page read and write
580000
heap
page read and write
4A4000
heap
page read and write
266A000
heap
page read and write
2160000
heap
page read and write
529000
heap
page read and write
There are 482 hidden memdumps, click here to show them.