IOC Report
FPPhfkcDCh.exe

loading gif

Files

File Path
Type
Category
Malicious
FPPhfkcDCh.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\ProgramData\rmc\logs.dat
data
dropped
malicious

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\FPPhfkcDCh.exe
"C:\Users\user\Desktop\FPPhfkcDCh.exe"
malicious

URLs

Name
IP
Malicious
http://geoplugin.net/json.gp
unknown
http://geoplugin.net/json.gp/C
unknown

IPs

IP
Domain
Country
Malicious
101.99.93.169
unknown
Malaysia
malicious
65.21.245.7
unknown
United States
malicious
103.144.139.157
unknown
unknown
malicious

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\SOFTWARE\one_fjyueo-T589A4
exepath
HKEY_CURRENT_USER\SOFTWARE\one_fjyueo-T589A4
licence
HKEY_CURRENT_USER\SOFTWARE\one_fjyueo-T589A4
time

Memdumps

Base Address
Regiontype
Protect
Malicious
6BE000
heap
page read and write
malicious
459000
unkown
page readonly
malicious
459000
unkown
page readonly
malicious
490000
heap
page read and write
471000
unkown
page read and write
401000
unkown
page execute read
400000
unkown
page readonly
400000
unkown
page readonly
7B0000
heap
page read and write
6B9000
heap
page read and write
9C000
stack
page read and write
9AF000
stack
page read and write
471000
unkown
page write copy
224F000
stack
page read and write
25EF000
stack
page read and write
19D000
stack
page read and write
228C000
stack
page read and write
515000
heap
page read and write
23EF000
stack
page read and write
401000
unkown
page execute read
22E0000
heap
page read and write
7C0000
heap
page read and write
474000
unkown
page read and write
22CE000
stack
page read and write
6B0000
heap
page read and write
66E000
stack
page read and write
272F000
stack
page read and write
6AC000
stack
page read and write
6ED000
heap
page read and write
478000
unkown
page readonly
1F0000
heap
page read and write
4DE000
stack
page read and write
4F0000
heap
page read and write
510000
heap
page read and write
24EF000
stack
page read and write
262E000
stack
page read and write
478000
unkown
page readonly
There are 27 hidden memdumps, click here to show them.