IOC Report
17323144242c7236b99d23fa10a9292bd7fb1c1fb47a26f3a8dc1daae9ecf25bbc7e35eb77810.dat-decoded.exe

loading gif

Files

File Path
Type
Category
Malicious
17323144242c7236b99d23fa10a9292bd7fb1c1fb47a26f3a8dc1daae9ecf25bbc7e35eb77810.dat-decoded.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\T9RRWRNL\json[1].json
JSON data
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\17323144242c7236b99d23fa10a9292bd7fb1c1fb47a26f3a8dc1daae9ecf25bbc7e35eb77810.dat-decoded.exe
"C:\Users\user\Desktop\17323144242c7236b99d23fa10a9292bd7fb1c1fb47a26f3a8dc1daae9ecf25bbc7e35eb77810.dat-decoded.exe"
malicious

URLs

Name
IP
Malicious
sostener.duckdns.org
malicious
http://geoplugin.net/json.gp
178.237.33.50
http://geoplugin.net/
unknown
http://geoplugin.net/s
unknown
http://geoplugin.net/json.gp/C
unknown
http://geoplugin.net/json.gpSystem32
unknown

Domains

Name
IP
Malicious
sostener.duckdns.org
191.91.176.72
malicious
geoplugin.net
178.237.33.50

IPs

IP
Domain
Country
Malicious
191.91.176.72
sostener.duckdns.org
Colombia
malicious
178.237.33.50
geoplugin.net
Netherlands

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\SOFTWARE\Rmc-P8SKN0
exepath
malicious
HKEY_CURRENT_USER\SOFTWARE\Rmc-P8SKN0
licence
malicious
HKEY_CURRENT_USER\SOFTWARE\Rmc-P8SKN0
time
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
457000
unkown
page readonly
malicious
457000
unkown
page readonly
malicious
480000
heap
page read and write
631000
heap
page read and write
4CE000
stack
page read and write
21F0000
heap
page read and write
8BF000
stack
page read and write
60F000
heap
page read and write
5CA000
heap
page read and write
620000
heap
page read and write
6C0000
heap
page read and write
631000
heap
page read and write
224E000
stack
page read and write
2D1F000
stack
page read and write
2C1E000
stack
page read and write
401000
unkown
page execute read
476000
unkown
page readonly
21EF000
stack
page read and write
476000
unkown
page readonly
400000
unkown
page readonly
643000
heap
page read and write
648000
heap
page read and write
4E0000
heap
page read and write
641000
heap
page read and write
600000
heap
page read and write
473000
unkown
page read and write
19C000
stack
page read and write
648000
heap
page read and write
5CE000
heap
page read and write
401000
unkown
page execute read
470000
unkown
page read and write
9C000
stack
page read and write
470000
unkown
page write copy
20DE000
stack
page read and write
234F000
stack
page read and write
4E6000
heap
page read and write
648000
heap
page read and write
400000
unkown
page readonly
60F000
heap
page read and write
20E0000
heap
page read and write
6D0000
heap
page read and write
5C0000
heap
page read and write
1F0000
heap
page read and write
There are 33 hidden memdumps, click here to show them.