IOC Report
1732341066786265aade6e9541774ff20509504237780da7874a65dc23bf44c6634c553abe427.dat-decoded.exe

loading gif

Files

File Path
Type
Category
Malicious
1732341066786265aade6e9541774ff20509504237780da7874a65dc23bf44c6634c553abe427.dat-decoded.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\ProgramData\escoclar\fox.dat
data
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\8HXJSKQQ\json[1].json
JSON data
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\1732341066786265aade6e9541774ff20509504237780da7874a65dc23bf44c6634c553abe427.dat-decoded.exe
"C:\Users\user\Desktop\1732341066786265aade6e9541774ff20509504237780da7874a65dc23bf44c6634c553abe427.dat-decoded.exe"
malicious

URLs

Name
IP
Malicious
escoclar.duckdns.org
malicious
http://geoplugin.net/json.gp
178.237.33.50
http://geoplugin.net/json.gpt
unknown
http://geoplugin.net/json.gpal
unknown
http://geoplugin.net/json.gp/C
unknown
http://geoplugin.net/json.gpl
unknown
http://geoplugin.net/json.gpSystem32
unknown
http://geoplugin.net/json.gpll
unknown
http://geoplugin.net/json.gp-
unknown

Domains

Name
IP
Malicious
escoclar.duckdns.org
154.216.17.204
malicious
geoplugin.net
178.237.33.50

IPs

IP
Domain
Country
Malicious
154.216.17.204
escoclar.duckdns.org
Seychelles
malicious
178.237.33.50
geoplugin.net
Netherlands

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\SOFTWARE\escoclar-5B94K9
exepath
HKEY_CURRENT_USER\SOFTWARE\escoclar-5B94K9
licence
HKEY_CURRENT_USER\SOFTWARE\escoclar-5B94K9
time

Memdumps

Base Address
Regiontype
Protect
Malicious
68E000
heap
page read and write
malicious
457000
unkown
page readonly
malicious
457000
unkown
page readonly
malicious
5CE000
stack
page read and write
550000
heap
page read and write
6F2000
heap
page read and write
703000
heap
page read and write
473000
unkown
page read and write
401000
unkown
page execute read
588000
heap
page read and write
23DC000
stack
page read and write
322F000
stack
page read and write
19C000
stack
page read and write
229E000
stack
page read and write
1F0000
heap
page read and write
6F2000
heap
page read and write
704000
heap
page read and write
9C000
stack
page read and write
312E000
stack
page read and write
6C1000
heap
page read and write
401000
unkown
page execute read
6D1000
heap
page read and write
790000
heap
page read and write
239F000
stack
page read and write
780000
heap
page read and write
650000
heap
page read and write
265E000
stack
page read and write
70B000
heap
page read and write
24DF000
stack
page read and write
580000
heap
page read and write
97F000
stack
page read and write
476000
unkown
page readonly
261F000
stack
page read and write
400000
unkown
page readonly
6D1000
heap
page read and write
68A000
heap
page read and write
289F000
stack
page read and write
251C000
stack
page read and write
470000
unkown
page read and write
275F000
stack
page read and write
70B000
heap
page read and write
2250000
heap
page read and write
400000
unkown
page readonly
476000
unkown
page readonly
470000
unkown
page write copy
680000
heap
page read and write
70B000
heap
page read and write
279E000
stack
page read and write
There are 38 hidden memdumps, click here to show them.