IOC Report
1732147507ac10953a908ae794c5ee180add9124a78c69705135688e502bb56ce4453da749198.dat-decoded.exe

loading gif

Files

File Path
Type
Category
Malicious
1732147507ac10953a908ae794c5ee180add9124a78c69705135688e502bb56ce4453da749198.dat-decoded.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\ProgramData\remcos\registros.dat
data
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\T9RRWRNL\json[1].json
JSON data
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\1732147507ac10953a908ae794c5ee180add9124a78c69705135688e502bb56ce4453da749198.dat-decoded.exe
"C:\Users\user\Desktop\1732147507ac10953a908ae794c5ee180add9124a78c69705135688e502bb56ce4453da749198.dat-decoded.exe"
malicious

URLs

Name
IP
Malicious
remcos2025rem.duckdns.org
malicious
http://geoplugin.net/json.gp
178.237.33.50
http://geoplugin.net/json.gp(1
unknown
http://geoplugin.net/json.gp/C
unknown
http://geoplugin.net/json.gp91n
unknown
http://geoplugin.net/json.gpl
unknown
http://geoplugin.net/json.gpSystem32
unknown

Domains

Name
IP
Malicious
remcos2025rem.duckdns.org
186.169.34.190
malicious
geoplugin.net
178.237.33.50

IPs

IP
Domain
Country
Malicious
186.169.34.190
remcos2025rem.duckdns.org
Colombia
malicious
178.237.33.50
geoplugin.net
Netherlands

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\SOFTWARE\Rmc-8AGIM5
exepath
malicious
HKEY_CURRENT_USER\SOFTWARE\Rmc-8AGIM5
licence
malicious
HKEY_CURRENT_USER\SOFTWARE\Rmc-8AGIM5
time
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
459000
unkown
page readonly
malicious
459000
unkown
page readonly
malicious
63E000
heap
page read and write
malicious
400000
unkown
page readonly
630000
heap
page read and write
6A3000
heap
page read and write
683000
heap
page read and write
401000
unkown
page execute read
224C000
stack
page read and write
6BE000
heap
page read and write
6C2000
heap
page read and write
400000
unkown
page readonly
6B1000
heap
page read and write
694000
heap
page read and write
570000
heap
page read and write
730000
heap
page read and write
24EE000
stack
page read and write
6B8000
heap
page read and write
683000
heap
page read and write
262E000
stack
page read and write
567000
heap
page read and write
9C000
stack
page read and write
6C2000
heap
page read and write
30EF000
stack
page read and write
478000
unkown
page readonly
471000
unkown
page read and write
23AC000
stack
page read and write
6C2000
heap
page read and write
272F000
stack
page read and write
6BE000
heap
page read and write
25EF000
stack
page read and write
6B8000
heap
page read and write
220F000
stack
page read and write
478000
unkown
page readonly
24AF000
stack
page read and write
474000
unkown
page read and write
674000
heap
page read and write
694000
heap
page read and write
560000
heap
page read and write
6B8000
heap
page read and write
610000
heap
page read and write
210E000
stack
page read and write
1F0000
heap
page read and write
6BE000
heap
page read and write
2FEE000
stack
page read and write
236F000
stack
page read and write
2260000
heap
page read and write
401000
unkown
page execute read
19C000
stack
page read and write
6B0000
heap
page read and write
471000
unkown
page write copy
63A000
heap
page read and write
6A3000
heap
page read and write
There are 43 hidden memdumps, click here to show them.