IOC Report
17323410671691fb610332a2a23e84df9d573b6d7d338d6835a49e8e0241717de8180586cb855.dat-decoded.exe

loading gif

Files

File Path
Type
Category
Malicious
17323410671691fb610332a2a23e84df9d573b6d7d338d6835a49e8e0241717de8180586cb855.dat-decoded.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\ProgramData\Asus\Book.dat
data
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3D003UC5\json[1].json
JSON data
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\17323410671691fb610332a2a23e84df9d573b6d7d338d6835a49e8e0241717de8180586cb855.dat-decoded.exe
"C:\Users\user\Desktop\17323410671691fb610332a2a23e84df9d573b6d7d338d6835a49e8e0241717de8180586cb855.dat-decoded.exe"
malicious

URLs

Name
IP
Malicious
shilajat.duckdns.org
malicious
http://geoplugin.net/json.gp
178.237.33.50
http://geoplugin.net/json.gp%1
unknown
http://geoplugin.net/
unknown
http://geoplugin.net/json.gp/C
unknown
http://geoplugin.net/json.gpSystem32
unknown

Domains

Name
IP
Malicious
shilajat.duckdns.org
154.216.17.204
malicious
geoplugin.net
178.237.33.50

IPs

IP
Domain
Country
Malicious
154.216.17.204
shilajat.duckdns.org
Seychelles
malicious
178.237.33.50
geoplugin.net
Netherlands

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\SOFTWARE\shilajit-ISLNRR
exepath
HKEY_CURRENT_USER\SOFTWARE\shilajit-ISLNRR
licence
HKEY_CURRENT_USER\SOFTWARE\shilajit-ISLNRR
time

Memdumps

Base Address
Regiontype
Protect
Malicious
7BE000
heap
page read and write
malicious
459000
unkown
page readonly
malicious
459000
unkown
page readonly
malicious
19C000
stack
page read and write
831000
heap
page read and write
5D0000
heap
page read and write
9AF000
stack
page read and write
9C000
stack
page read and write
560000
heap
page read and write
7B0000
heap
page read and write
471000
unkown
page write copy
7BA000
heap
page read and write
1F0000
heap
page read and write
5C0000
heap
page read and write
474000
unkown
page read and write
401000
unkown
page execute read
2FEE000
stack
page read and write
238F000
stack
page read and write
260F000
stack
page read and write
5AE000
stack
page read and write
710000
heap
page read and write
471000
unkown
page read and write
7FF000
heap
page read and write
400000
unkown
page readonly
250E000
stack
page read and write
478000
unkown
page readonly
77E000
stack
page read and write
730000
heap
page read and write
823000
heap
page read and write
7FF000
heap
page read and write
224F000
stack
page read and write
228C000
stack
page read and write
823000
heap
page read and write
274F000
stack
page read and write
838000
heap
page read and write
401000
unkown
page execute read
30EF000
stack
page read and write
478000
unkown
page readonly
838000
heap
page read and write
400000
unkown
page readonly
82F000
heap
page read and write
838000
heap
page read and write
7F0000
heap
page read and write
23CC000
stack
page read and write
264E000
stack
page read and write
5C7000
heap
page read and write
24CF000
stack
page read and write
There are 37 hidden memdumps, click here to show them.