Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
1m70ggeepT.exe
|
PE32 executable (GUI) Intel 80386, for MS Windows
|
initial sample
|
||
C:\Users\user\AppData\Roaming\microsofts\svcs.exe
|
PE32 executable (GUI) Intel 80386, for MS Windows
|
dropped
|
||
C:\ProgramData\logsa\logs.dat
|
data
|
dropped
|
||
C:\Users\user\AppData\Roaming\microsofts\svcs.exe:Zone.Identifier
|
ASCII text, with CRLF line terminators
|
modified
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\1m70ggeepT.exe
|
"C:\Users\user\Desktop\1m70ggeepT.exe"
|
||
C:\Users\user\AppData\Roaming\microsofts\svcs.exe
|
"C:\Users\user\AppData\Roaming\microsofts\svcs.exe"
|
||
C:\Users\user\AppData\Roaming\microsofts\svcs.exe
|
"C:\Users\user\AppData\Roaming\microsofts\svcs.exe"
|
||
C:\Users\user\AppData\Roaming\microsofts\svcs.exe
|
"C:\Users\user\AppData\Roaming\microsofts\svcs.exe"
|
||
C:\Users\user\AppData\Roaming\microsofts\svcs.exe
|
"C:\Users\user\AppData\Roaming\microsofts\svcs.exe"
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://geoplugin.net/json.gp
|
unknown
|
||
http://geoplugin.net/json.gp/C
|
unknown
|
||
leetboy.dynuddns.net
|
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
leetboy.dynuddns.net
|
185.196.11.223
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
185.196.11.223
|
leetboy.dynuddns.net
|
Switzerland
|
Registry
Path
|
Value
|
Malicious
|
|
---|---|---|---|
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
|
Rmc-3XK1S0
|
||
HKEY_CURRENT_USER\SOFTWARE\Rmc-3XK1S0
|
exepath
|
||
HKEY_CURRENT_USER\SOFTWARE\Rmc-3XK1S0
|
licence
|
||
HKEY_CURRENT_USER\SOFTWARE\Rmc-3XK1S0
|
time
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run
|
Rmc-3XK1S0
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
459000
|
unkown
|
page readonly
|
||
459000
|
unkown
|
page readonly
|
||
459000
|
unkown
|
page readonly
|
||
459000
|
unkown
|
page readonly
|
||
459000
|
unkown
|
page readonly
|
||
5C7000
|
heap
|
page read and write
|
||
459000
|
unkown
|
page readonly
|
||
459000
|
unkown
|
page readonly
|
||
459000
|
unkown
|
page readonly
|
||
459000
|
unkown
|
page readonly
|
||
459000
|
unkown
|
page readonly
|
||
76E000
|
heap
|
page read and write
|
||
236F000
|
stack
|
page read and write
|
||
226C000
|
stack
|
page read and write
|
||
401000
|
unkown
|
page execute read
|
||
610000
|
heap
|
page read and write
|
||
401000
|
unkown
|
page execute read
|
||
65A000
|
heap
|
page read and write
|
||
478000
|
unkown
|
page readonly
|
||
60E000
|
stack
|
page read and write
|
||
691000
|
heap
|
page read and write
|
||
297F000
|
stack
|
page read and write
|
||
471000
|
unkown
|
page write copy
|
||
4D0000
|
heap
|
page read and write
|
||
2ABF000
|
stack
|
page read and write
|
||
478000
|
unkown
|
page readonly
|
||
25F0000
|
heap
|
page read and write
|
||
25EF000
|
stack
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
270F000
|
unkown
|
page read and write
|
||
474000
|
unkown
|
page read and write
|
||
79B000
|
heap
|
page read and write
|
||
6DE000
|
stack
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
19D000
|
stack
|
page read and write
|
||
80E000
|
stack
|
page read and write
|
||
750000
|
heap
|
page read and write
|
||
98F000
|
stack
|
page read and write
|
||
95E000
|
stack
|
page read and write
|
||
5B0000
|
heap
|
page read and write
|
||
505000
|
heap
|
page read and write
|
||
80E000
|
stack
|
page read and write
|
||
4CE000
|
stack
|
page read and write
|
||
478000
|
unkown
|
page readonly
|
||
1F0000
|
heap
|
page read and write
|
||
401000
|
unkown
|
page execute read
|
||
90F000
|
stack
|
page read and write
|
||
25EE000
|
stack
|
page read and write
|
||
262E000
|
stack
|
page read and write
|
||
760000
|
heap
|
page read and write
|
||
94F000
|
stack
|
page read and write
|
||
4CE000
|
stack
|
page read and write
|
||
84E000
|
stack
|
page read and write
|
||
9C000
|
stack
|
page read and write
|
||
401000
|
unkown
|
page execute read
|
||
540000
|
heap
|
page read and write
|
||
471000
|
unkown
|
page write copy
|
||
9B000
|
stack
|
page read and write
|
||
21A0000
|
heap
|
page read and write
|
||
19D000
|
stack
|
page read and write
|
||
471000
|
unkown
|
page read and write
|
||
1F0000
|
heap
|
page read and write
|
||
65E000
|
heap
|
page read and write
|
||
2670000
|
heap
|
page read and write
|
||
478000
|
unkown
|
page readonly
|
||
4CE000
|
stack
|
page read and write
|
||
471000
|
unkown
|
page read and write
|
||
1F0000
|
heap
|
page read and write
|
||
19C000
|
stack
|
page read and write
|
||
471000
|
unkown
|
page read and write
|
||
500000
|
heap
|
page read and write
|
||
478000
|
unkown
|
page readonly
|
||
478000
|
unkown
|
page readonly
|
||
400000
|
unkown
|
page readonly
|
||
287F000
|
stack
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
400000
|
unkown
|
page readonly
|
||
4DE000
|
stack
|
page read and write
|
||
474000
|
unkown
|
page read and write
|
||
2AFE000
|
stack
|
page read and write
|
||
2210000
|
heap
|
page read and write
|
||
94F000
|
stack
|
page read and write
|
||
617000
|
heap
|
page read and write
|
||
401000
|
unkown
|
page execute read
|
||
71E000
|
stack
|
page read and write
|
||
2C3C000
|
stack
|
page read and write
|
||
5C0000
|
heap
|
page read and write
|
||
88E000
|
stack
|
page read and write
|
||
471000
|
unkown
|
page write copy
|
||
401000
|
unkown
|
page execute read
|
||
474000
|
unkown
|
page read and write
|
||
760000
|
heap
|
page read and write
|
||
471000
|
unkown
|
page write copy
|
||
490000
|
heap
|
page read and write
|
||
478000
|
unkown
|
page readonly
|
||
4F0000
|
heap
|
page read and write
|
||
630000
|
heap
|
page read and write
|
||
401000
|
unkown
|
page execute read
|
||
4D0000
|
heap
|
page read and write
|
||
650000
|
heap
|
page read and write
|
||
590000
|
heap
|
page read and write
|
||
21A0000
|
heap
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
76A000
|
heap
|
page read and write
|
||
471000
|
unkown
|
page read and write
|
||
2BFF000
|
stack
|
page read and write
|
||
277E000
|
stack
|
page read and write
|
||
474000
|
unkown
|
page read and write
|
||
550000
|
heap
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
471000
|
unkown
|
page read and write
|
||
560000
|
heap
|
page read and write
|
||
212E000
|
stack
|
page read and write
|
||
1F0000
|
heap
|
page read and write
|
||
9C000
|
stack
|
page read and write
|
||
24EE000
|
stack
|
page read and write
|
||
51E000
|
stack
|
page read and write
|
||
24AF000
|
stack
|
page read and write
|
||
474000
|
unkown
|
page read and write
|
||
61E000
|
stack
|
page read and write
|
||
9C000
|
stack
|
page read and write
|
||
478000
|
unkown
|
page readonly
|
||
19A000
|
stack
|
page read and write
|
||
222F000
|
stack
|
page read and write
|
||
595000
|
heap
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
62C000
|
heap
|
page read and write
|
||
401000
|
unkown
|
page execute read
|
||
266E000
|
stack
|
page read and write
|
||
471000
|
unkown
|
page write copy
|
||
547000
|
heap
|
page read and write
|
||
29BE000
|
stack
|
page read and write
|
||
23AC000
|
stack
|
page read and write
|
||
720000
|
heap
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
401000
|
unkown
|
page execute read
|
||
1F0000
|
heap
|
page read and write
|
||
5DE000
|
stack
|
page read and write
|
||
478000
|
unkown
|
page readonly
|
||
401000
|
unkown
|
page execute read
|
||
2D3C000
|
stack
|
page read and write
|
||
478000
|
unkown
|
page readonly
|
||
4D0000
|
heap
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
510000
|
heap
|
page read and write
|
||
9C000
|
stack
|
page read and write
|
||
19D000
|
stack
|
page read and write
|
There are 137 hidden memdumps, click here to show them.