IOC Report
1732143786cec792bea7f8ce7f818c031173ce52fabd19dde842f74b07fc234dc9f3fa1dcf839.dat-decoded.exe

loading gif

Files

File Path
Type
Category
Malicious
1732143786cec792bea7f8ce7f818c031173ce52fabd19dde842f74b07fc234dc9f3fa1dcf839.dat-decoded.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\ProgramData\remcos\registros.dat
data
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\T9RRWRNL\json[1].json
JSON data
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\1732143786cec792bea7f8ce7f818c031173ce52fabd19dde842f74b07fc234dc9f3fa1dcf839.dat-decoded.exe
"C:\Users\user\Desktop\1732143786cec792bea7f8ce7f818c031173ce52fabd19dde842f74b07fc234dc9f3fa1dcf839.dat-decoded.exe"
malicious

URLs

Name
IP
Malicious
remcosnov24.duckdns.org
malicious
http://geoplugin.net/json.gp
178.237.33.50
http://geoplugin.net/json.gpQ(
unknown
http://geoplugin.net/
unknown
http://geoplugin.net/json.gp5
unknown
http://geoplugin.net/json.gp/C
unknown
http://geoplugin.net/json.gpSystem32
unknown
http://geoplugin.net/json.gpp
unknown

Domains

Name
IP
Malicious
remcosnov24.duckdns.org
190.9.223.135
malicious
geoplugin.net
178.237.33.50

IPs

IP
Domain
Country
Malicious
190.9.223.135
remcosnov24.duckdns.org
Colombia
malicious
178.237.33.50
geoplugin.net
Netherlands

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\SOFTWARE\Rmc-0883UG
exepath
malicious
HKEY_CURRENT_USER\SOFTWARE\Rmc-0883UG
licence
malicious
HKEY_CURRENT_USER\SOFTWARE\Rmc-0883UG
time
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
457000
unkown
page readonly
malicious
53E000
heap
page read and write
malicious
457000
unkown
page readonly
malicious
530000
heap
page read and write
25CF000
stack
page read and write
53A000
heap
page read and write
2FDE000
stack
page read and write
401000
unkown
page execute read
581000
heap
page read and write
1C0000
heap
page read and write
401000
unkown
page execute read
24CE000
stack
page read and write
221C000
stack
page read and write
5B1000
heap
page read and write
5AA000
heap
page read and write
4DE000
stack
page read and write
5AF000
heap
page read and write
2240000
heap
page read and write
470000
unkown
page read and write
9C000
stack
page read and write
476000
unkown
page readonly
572000
heap
page read and write
260E000
stack
page read and write
238C000
stack
page read and write
270F000
stack
page read and write
5A0000
heap
page read and write
476000
unkown
page readonly
473000
unkown
page read and write
1C7000
heap
page read and write
5B6000
heap
page read and write
20DE000
stack
page read and write
21DF000
stack
page read and write
209F000
stack
page read and write
400000
unkown
page readonly
19C000
stack
page read and write
2220000
heap
page read and write
5B6000
heap
page read and write
490000
heap
page read and write
480000
heap
page read and write
400000
unkown
page readonly
700000
heap
page read and write
5B6000
heap
page read and write
5A0000
heap
page read and write
234F000
stack
page read and write
470000
unkown
page write copy
5AA000
heap
page read and write
30DF000
stack
page read and write
581000
heap
page read and write
248F000
stack
page read and write
There are 39 hidden memdumps, click here to show them.