Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
17304052250b9baaf5a761ccc772d95d677ec70f56bbae9f30fbbf26b5b71b9b9867fc8bb2802.dat-decoded.exe
|
PE32 executable (GUI) Intel 80386, for MS Windows
|
initial sample
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\BEDT2L3A\json[1].json
|
JSON data
|
dropped
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\17304052250b9baaf5a761ccc772d95d677ec70f56bbae9f30fbbf26b5b71b9b9867fc8bb2802.dat-decoded.exe
|
"C:\Users\user\Desktop\17304052250b9baaf5a761ccc772d95d677ec70f56bbae9f30fbbf26b5b71b9b9867fc8bb2802.dat-decoded.exe"
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
rem.aaahorneswll.com
|
|||
http://geoplugin.net/json.gp
|
178.237.33.50
|
||
http://geoplugin.net/json.gp1
|
unknown
|
||
http://geoplugin.net/
|
unknown
|
||
http://geoplugin.net/json.gp/C
|
unknown
|
||
http://geoplugin.net/json.gpl
|
unknown
|
||
http://geoplugin.net/json.gpSystem32
|
unknown
|
||
http://geoplugin.net/json.gp3U
|
unknown
|
||
http://geoplugin.net/json.gpCT
|
unknown
|
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
geoplugin.net
|
178.237.33.50
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
80.76.51.190
|
unknown
|
Bulgaria
|
||
178.237.33.50
|
geoplugin.net
|
Netherlands
|
Registry
Path
|
Value
|
Malicious
|
|
---|---|---|---|
HKEY_CURRENT_USER\SOFTWARE\Rmc-XH0QAV
|
exepath
|
||
HKEY_CURRENT_USER\SOFTWARE\Rmc-XH0QAV
|
licence
|
||
HKEY_CURRENT_USER\SOFTWARE\Rmc-XH0QAV
|
time
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
459000
|
unkown
|
page readonly
|
||
459000
|
unkown
|
page readonly
|
||
5DE000
|
heap
|
page read and write
|
||
214E000
|
stack
|
page read and write
|
||
5DA000
|
heap
|
page read and write
|
||
226F000
|
stack
|
page read and write
|
||
66D000
|
heap
|
page read and write
|
||
62D000
|
heap
|
page read and write
|
||
570000
|
heap
|
page read and write
|
||
471000
|
unkown
|
page write copy
|
||
400000
|
unkown
|
page readonly
|
||
2D3F000
|
stack
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
671000
|
heap
|
page read and write
|
||
665000
|
heap
|
page read and write
|
||
9C000
|
stack
|
page read and write
|
||
20F0000
|
heap
|
page read and write
|
||
61D000
|
heap
|
page read and write
|
||
2C3E000
|
stack
|
page read and write
|
||
60E000
|
heap
|
page read and write
|
||
471000
|
unkown
|
page read and write
|
||
20EE000
|
stack
|
page read and write
|
||
667000
|
heap
|
page read and write
|
||
478000
|
unkown
|
page readonly
|
||
1E0000
|
heap
|
page read and write
|
||
478000
|
unkown
|
page readonly
|
||
8CF000
|
stack
|
page read and write
|
||
678000
|
heap
|
page read and write
|
||
5BE000
|
stack
|
page read and write
|
||
401000
|
unkown
|
page execute read
|
||
1E7000
|
heap
|
page read and write
|
||
678000
|
heap
|
page read and write
|
||
678000
|
heap
|
page read and write
|
||
19D000
|
stack
|
page read and write
|
||
651000
|
heap
|
page read and write
|
||
236F000
|
stack
|
page read and write
|
||
65F000
|
heap
|
page read and write
|
||
671000
|
heap
|
page read and write
|
||
665000
|
heap
|
page read and write
|
||
6D0000
|
heap
|
page read and write
|
||
667000
|
heap
|
page read and write
|
||
2160000
|
heap
|
page read and write
|
||
66D000
|
heap
|
page read and write
|
||
490000
|
heap
|
page read and write
|
||
671000
|
heap
|
page read and write
|
||
667000
|
heap
|
page read and write
|
||
651000
|
heap
|
page read and write
|
||
474000
|
unkown
|
page read and write
|
||
661000
|
heap
|
page read and write
|
||
66D000
|
heap
|
page read and write
|
||
5D0000
|
heap
|
page read and write
|
||
61D000
|
heap
|
page read and write
|
||
401000
|
unkown
|
page execute read
|
There are 43 hidden memdumps, click here to show them.