IOC Report
17323410673807b67d8bb6f66f1d676167634fbe15d4743d1d486ea52ce68855c1615ccc44621.dat-decoded.exe

loading gif

Files

File Path
Type
Category
Malicious
17323410673807b67d8bb6f66f1d676167634fbe15d4743d1d486ea52ce68855c1615ccc44621.dat-decoded.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\ProgramData\chiqui\back.dat
data
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\17323410673807b67d8bb6f66f1d676167634fbe15d4743d1d486ea52ce68855c1615ccc44621.dat-decoded.exe
"C:\Users\user\Desktop\17323410673807b67d8bb6f66f1d676167634fbe15d4743d1d486ea52ce68855c1615ccc44621.dat-decoded.exe"
malicious

URLs

Name
IP
Malicious
shilajat.duckdns.org
malicious
http://geoplugin.net/json.gp
unknown
http://geoplugin.net/json.gp/C
unknown

Domains

Name
IP
Malicious
shilajat.duckdns.org
154.216.17.204
malicious
s-part-0035.t-0009.t-msedge.net
13.107.246.63

IPs

IP
Domain
Country
Malicious
154.216.17.204
shilajat.duckdns.org
Seychelles
malicious

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\SOFTWARE\iphone-SP6UL4
exepath
HKEY_CURRENT_USER\SOFTWARE\iphone-SP6UL4
licence
HKEY_CURRENT_USER\SOFTWARE\iphone-SP6UL4
time

Memdumps

Base Address
Regiontype
Protect
Malicious
459000
unkown
page readonly
malicious
5BE000
heap
page read and write
malicious
459000
unkown
page readonly
malicious
5BA000
heap
page read and write
400000
unkown
page readonly
7EF000
stack
page read and write
471000
unkown
page read and write
229F000
stack
page read and write
24DE000
stack
page read and write
1D0000
heap
page read and write
478000
unkown
page readonly
239F000
stack
page read and write
401000
unkown
page execute read
471000
unkown
page write copy
6EE000
stack
page read and write
218C000
stack
page read and write
92E000
stack
page read and write
474000
unkown
page read and write
490000
heap
page read and write
1D7000
heap
page read and write
5B0000
heap
page read and write
214C000
stack
page read and write
590000
heap
page read and write
26DF000
stack
page read and write
400000
unkown
page readonly
478000
unkown
page readonly
7F0000
heap
page read and write
249F000
stack
page read and write
210E000
stack
page read and write
570000
heap
page read and write
2190000
heap
page read and write
401000
unkown
page execute read
19C000
stack
page read and write
9C000
stack
page read and write
25DF000
stack
page read and write
There are 25 hidden memdumps, click here to show them.