IOC Report
1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe

loading gif

Files

File Path
Type
Category
Malicious
1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Roaming\188E93\31437F.lck
very short file (no magic)
dropped
C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-2246122658-3693405117-2476756634-1002\bc49718863ee53e026d805ec372039e9_9e146be9-c76a-4720-bcdb-53011b87bd06
data
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe
"C:\Users\user\Desktop\1729844285df3beefdd998d9488ed81285c601b4206d2d286448af87fbe46e5e262d812b0f698.dat-decoded.exe"
malicious

URLs

Name
IP
Malicious
http://94.156.177.220/simple/five/fre.php
94.156.177.220
malicious
http://kbfvzoboss.bid/alien/fre.php
malicious
http://alphastand.win/alien/fre.php
malicious
http://alphastand.trade/alien/fre.php
malicious
http://alphastand.top/alien/fre.php
malicious
http://www.ibsensoftware.com/
unknown

IPs

IP
Domain
Country
Malicious
94.156.177.220
unknown
Bulgaria
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
415000
unkown
page readonly
malicious
415000
unkown
page readonly
malicious
83E000
heap
page read and write
malicious
2270000
heap
page read and write
27C0000
heap
page read and write
680000
heap
page read and write
401000
unkown
page execute read
830000
heap
page read and write
620000
heap
page read and write
650000
direct allocation
page read and write
27D0000
heap
page read and write
650000
direct allocation
page read and write
26BF000
stack
page read and write
686000
heap
page read and write
19C000
stack
page read and write
401000
unkown
page execute read
400000
unkown
page readonly
83A000
heap
page read and write
80E000
stack
page read and write
655000
direct allocation
page read and write
4A0000
unkown
page write copy
27BF000
stack
page read and write
7CE000
stack
page read and write
9C000
stack
page read and write
5CE000
stack
page read and write
580000
heap
page read and write
4A0000
unkown
page read and write
1F0000
heap
page read and write
400000
unkown
page readonly
78F000
stack
page read and write
There are 20 hidden memdumps, click here to show them.