IOC Report
17323410667d99229b9ce677d696d20502ddaab36e60066e7988d89e342c219aec646f9f24501.dat-decoded.exe

loading gif

Files

File Path
Type
Category
Malicious
17323410667d99229b9ce677d696d20502ddaab36e60066e7988d89e342c219aec646f9f24501.dat-decoded.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\ProgramData\windir\ops.dat
data
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\17323410667d99229b9ce677d696d20502ddaab36e60066e7988d89e342c219aec646f9f24501.dat-decoded.exe
"C:\Users\user\Desktop\17323410667d99229b9ce677d696d20502ddaab36e60066e7988d89e342c219aec646f9f24501.dat-decoded.exe"
malicious

URLs

Name
IP
Malicious
championsleague24.duckdns.org
malicious
http://geoplugin.net/json.gp
unknown
http://geoplugin.net/json.gp/C
unknown

Domains

Name
IP
Malicious
championsleague24.duckdns.org
180.19.180.122
malicious

IPs

IP
Domain
Country
Malicious
180.19.180.122
championsleague24.duckdns.org
Japan
malicious

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\SOFTWARE\wsbdetrdfeyt45-ZLEH2L
exepath
HKEY_CURRENT_USER\SOFTWARE\wsbdetrdfeyt45-ZLEH2L
licence
HKEY_CURRENT_USER\SOFTWARE\wsbdetrdfeyt45-ZLEH2L
time

Memdumps

Base Address
Regiontype
Protect
Malicious
459000
unkown
page readonly
malicious
7BE000
heap
page read and write
malicious
459000
unkown
page readonly
malicious
560000
heap
page read and write
478000
unkown
page readonly
600000
heap
page read and write
19C000
stack
page read and write
1F0000
heap
page read and write
260F000
stack
page read and write
401000
unkown
page execute read
620000
heap
page read and write
474000
unkown
page read and write
400000
unkown
page readonly
471000
unkown
page read and write
401000
unkown
page execute read
23CC000
stack
page read and write
74F000
stack
page read and write
224F000
stack
page read and write
2610000
heap
page read and write
9C000
stack
page read and write
250E000
stack
page read and write
5AE000
stack
page read and write
7B0000
heap
page read and write
9AF000
stack
page read and write
2620000
heap
page read and write
78E000
stack
page read and write
5EE000
stack
page read and write
471000
unkown
page write copy
478000
unkown
page readonly
640000
heap
page read and write
24CF000
stack
page read and write
400000
unkown
page readonly
228C000
stack
page read and write
646000
heap
page read and write
7BA000
heap
page read and write
238F000
stack
page read and write
There are 26 hidden memdumps, click here to show them.