IOC Report
17304052250b9baaf5a761ccc772d95d677ec70f56bbae9f30fbbf26b5b71b9b9867fc8bb2802.dat-decoded.exe

loading gif

Files

File Path
Type
Category
Malicious
17304052250b9baaf5a761ccc772d95d677ec70f56bbae9f30fbbf26b5b71b9b9867fc8bb2802.dat-decoded.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\BEDT2L3A\json[1].json
JSON data
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\17304052250b9baaf5a761ccc772d95d677ec70f56bbae9f30fbbf26b5b71b9b9867fc8bb2802.dat-decoded.exe
"C:\Users\user\Desktop\17304052250b9baaf5a761ccc772d95d677ec70f56bbae9f30fbbf26b5b71b9b9867fc8bb2802.dat-decoded.exe"
malicious

URLs

Name
IP
Malicious
rem.aaahorneswll.com
malicious
http://geoplugin.net/json.gp
178.237.33.50
http://geoplugin.net/json.gp1
unknown
http://geoplugin.net/
unknown
http://geoplugin.net/json.gp/C
unknown
http://geoplugin.net/json.gpl
unknown
http://geoplugin.net/json.gpSystem32
unknown
http://geoplugin.net/json.gp3U
unknown
http://geoplugin.net/json.gpCT
unknown

Domains

Name
IP
Malicious
geoplugin.net
178.237.33.50

IPs

IP
Domain
Country
Malicious
80.76.51.190
unknown
Bulgaria
malicious
178.237.33.50
geoplugin.net
Netherlands

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\SOFTWARE\Rmc-XH0QAV
exepath
malicious
HKEY_CURRENT_USER\SOFTWARE\Rmc-XH0QAV
licence
malicious
HKEY_CURRENT_USER\SOFTWARE\Rmc-XH0QAV
time
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
459000
unkown
page readonly
malicious
459000
unkown
page readonly
malicious
5DE000
heap
page read and write
malicious
214E000
stack
page read and write
5DA000
heap
page read and write
226F000
stack
page read and write
66D000
heap
page read and write
62D000
heap
page read and write
570000
heap
page read and write
471000
unkown
page write copy
400000
unkown
page readonly
2D3F000
stack
page read and write
400000
unkown
page readonly
671000
heap
page read and write
665000
heap
page read and write
9C000
stack
page read and write
20F0000
heap
page read and write
61D000
heap
page read and write
2C3E000
stack
page read and write
60E000
heap
page read and write
471000
unkown
page read and write
20EE000
stack
page read and write
667000
heap
page read and write
478000
unkown
page readonly
1E0000
heap
page read and write
478000
unkown
page readonly
8CF000
stack
page read and write
678000
heap
page read and write
5BE000
stack
page read and write
401000
unkown
page execute read
1E7000
heap
page read and write
678000
heap
page read and write
678000
heap
page read and write
19D000
stack
page read and write
651000
heap
page read and write
236F000
stack
page read and write
65F000
heap
page read and write
671000
heap
page read and write
665000
heap
page read and write
6D0000
heap
page read and write
667000
heap
page read and write
2160000
heap
page read and write
66D000
heap
page read and write
490000
heap
page read and write
671000
heap
page read and write
667000
heap
page read and write
651000
heap
page read and write
474000
unkown
page read and write
661000
heap
page read and write
66D000
heap
page read and write
5D0000
heap
page read and write
61D000
heap
page read and write
401000
unkown
page execute read
There are 43 hidden memdumps, click here to show them.