IOC Report
17323410667d9914389510ca21e4da9d52e0e3e1cf605c3d0e38cbeee51b87b9fe9bfcb9f3306.dat-decoded.exe

loading gif

Files

File Path
Type
Category
Malicious
17323410667d9914389510ca21e4da9d52e0e3e1cf605c3d0e38cbeee51b87b9fe9bfcb9f3306.dat-decoded.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\ProgramData\windir\ops2.dat
data
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\17323410667d9914389510ca21e4da9d52e0e3e1cf605c3d0e38cbeee51b87b9fe9bfcb9f3306.dat-decoded.exe
"C:\Users\user\Desktop\17323410667d9914389510ca21e4da9d52e0e3e1cf605c3d0e38cbeee51b87b9fe9bfcb9f3306.dat-decoded.exe"
malicious

URLs

Name
IP
Malicious
championsleague24.duckdns.org
malicious
http://geoplugin.net/json.gp
unknown
http://geoplugin.net/json.gp/C
unknown

Domains

Name
IP
Malicious
championsleague24.duckdns.org
180.19.180.122
malicious

IPs

IP
Domain
Country
Malicious
180.19.180.122
championsleague24.duckdns.org
Japan
malicious

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\SOFTWARE\wsbdetrdfeyt45-3U0BF6
exepath
HKEY_CURRENT_USER\SOFTWARE\wsbdetrdfeyt45-3U0BF6
licence
HKEY_CURRENT_USER\SOFTWARE\wsbdetrdfeyt45-3U0BF6
time

Memdumps

Base Address
Regiontype
Protect
Malicious
457000
unkown
page readonly
malicious
6BE000
heap
page read and write
malicious
457000
unkown
page readonly
malicious
25E0000
heap
page read and write
20DE000
stack
page read and write
6BA000
heap
page read and write
8AF000
stack
page read and write
9C000
stack
page read and write
22CF000
stack
page read and write
400000
unkown
page readonly
4D6000
heap
page read and write
211C000
stack
page read and write
219E000
stack
page read and write
5EE000
stack
page read and write
24CF000
stack
page read and write
473000
unkown
page read and write
4D0000
heap
page read and write
476000
unkown
page readonly
1F0000
heap
page read and write
23CF000
stack
page read and write
401000
unkown
page execute read
21A0000
heap
page read and write
480000
heap
page read and write
401000
unkown
page execute read
25D0000
heap
page read and write
470000
unkown
page read and write
215C000
stack
page read and write
6B0000
heap
page read and write
19C000
stack
page read and write
470000
unkown
page write copy
25CF000
stack
page read and write
21C0000
heap
page read and write
400000
unkown
page readonly
476000
unkown
page readonly
There are 24 hidden memdumps, click here to show them.