IOC Report
1m70ggeepT.exe

loading gif

Files

File Path
Type
Category
Malicious
1m70ggeepT.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Roaming\microsofts\svcs.exe
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\ProgramData\logsa\logs.dat
data
dropped
C:\Users\user\AppData\Roaming\microsofts\svcs.exe:Zone.Identifier
ASCII text, with CRLF line terminators
modified

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\1m70ggeepT.exe
"C:\Users\user\Desktop\1m70ggeepT.exe"
malicious
C:\Users\user\AppData\Roaming\microsofts\svcs.exe
"C:\Users\user\AppData\Roaming\microsofts\svcs.exe"
malicious
C:\Users\user\AppData\Roaming\microsofts\svcs.exe
"C:\Users\user\AppData\Roaming\microsofts\svcs.exe"
malicious
C:\Users\user\AppData\Roaming\microsofts\svcs.exe
"C:\Users\user\AppData\Roaming\microsofts\svcs.exe"
malicious
C:\Users\user\AppData\Roaming\microsofts\svcs.exe
"C:\Users\user\AppData\Roaming\microsofts\svcs.exe"
malicious

URLs

Name
IP
Malicious
http://geoplugin.net/json.gp
unknown
malicious
http://geoplugin.net/json.gp/C
unknown
malicious
leetboy.dynuddns.net
malicious

Domains

Name
IP
Malicious
leetboy.dynuddns.net
185.196.11.223
malicious

IPs

IP
Domain
Country
Malicious
185.196.11.223
leetboy.dynuddns.net
Switzerland
malicious

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Rmc-3XK1S0
malicious
HKEY_CURRENT_USER\SOFTWARE\Rmc-3XK1S0
exepath
malicious
HKEY_CURRENT_USER\SOFTWARE\Rmc-3XK1S0
licence
malicious
HKEY_CURRENT_USER\SOFTWARE\Rmc-3XK1S0
time
malicious
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run
Rmc-3XK1S0

Memdumps

Base Address
Regiontype
Protect
Malicious
459000
unkown
page readonly
malicious
459000
unkown
page readonly
malicious
459000
unkown
page readonly
malicious
459000
unkown
page readonly
malicious
459000
unkown
page readonly
malicious
5C7000
heap
page read and write
malicious
459000
unkown
page readonly
malicious
459000
unkown
page readonly
malicious
459000
unkown
page readonly
malicious
459000
unkown
page readonly
malicious
459000
unkown
page readonly
malicious
76E000
heap
page read and write
malicious
236F000
stack
page read and write
226C000
stack
page read and write
401000
unkown
page execute read
610000
heap
page read and write
401000
unkown
page execute read
65A000
heap
page read and write
478000
unkown
page readonly
60E000
stack
page read and write
691000
heap
page read and write
297F000
stack
page read and write
471000
unkown
page write copy
4D0000
heap
page read and write
2ABF000
stack
page read and write
478000
unkown
page readonly
25F0000
heap
page read and write
25EF000
stack
page read and write
400000
unkown
page readonly
270F000
unkown
page read and write
474000
unkown
page read and write
79B000
heap
page read and write
6DE000
stack
page read and write
400000
unkown
page readonly
19D000
stack
page read and write
80E000
stack
page read and write
750000
heap
page read and write
98F000
stack
page read and write
95E000
stack
page read and write
5B0000
heap
page read and write
505000
heap
page read and write
80E000
stack
page read and write
4CE000
stack
page read and write
478000
unkown
page readonly
1F0000
heap
page read and write
401000
unkown
page execute read
90F000
stack
page read and write
25EE000
stack
page read and write
262E000
stack
page read and write
760000
heap
page read and write
94F000
stack
page read and write
4CE000
stack
page read and write
84E000
stack
page read and write
9C000
stack
page read and write
401000
unkown
page execute read
540000
heap
page read and write
471000
unkown
page write copy
9B000
stack
page read and write
21A0000
heap
page read and write
19D000
stack
page read and write
471000
unkown
page read and write
1F0000
heap
page read and write
65E000
heap
page read and write
2670000
heap
page read and write
478000
unkown
page readonly
4CE000
stack
page read and write
471000
unkown
page read and write
1F0000
heap
page read and write
19C000
stack
page read and write
471000
unkown
page read and write
500000
heap
page read and write
478000
unkown
page readonly
478000
unkown
page readonly
400000
unkown
page readonly
287F000
stack
page read and write
400000
unkown
page readonly
400000
unkown
page readonly
4DE000
stack
page read and write
474000
unkown
page read and write
2AFE000
stack
page read and write
2210000
heap
page read and write
94F000
stack
page read and write
617000
heap
page read and write
401000
unkown
page execute read
71E000
stack
page read and write
2C3C000
stack
page read and write
5C0000
heap
page read and write
88E000
stack
page read and write
471000
unkown
page write copy
401000
unkown
page execute read
474000
unkown
page read and write
760000
heap
page read and write
471000
unkown
page write copy
490000
heap
page read and write
478000
unkown
page readonly
4F0000
heap
page read and write
630000
heap
page read and write
401000
unkown
page execute read
4D0000
heap
page read and write
650000
heap
page read and write
590000
heap
page read and write
21A0000
heap
page read and write
400000
unkown
page readonly
76A000
heap
page read and write
471000
unkown
page read and write
2BFF000
stack
page read and write
277E000
stack
page read and write
474000
unkown
page read and write
550000
heap
page read and write
400000
unkown
page readonly
471000
unkown
page read and write
560000
heap
page read and write
212E000
stack
page read and write
1F0000
heap
page read and write
9C000
stack
page read and write
24EE000
stack
page read and write
51E000
stack
page read and write
24AF000
stack
page read and write
474000
unkown
page read and write
61E000
stack
page read and write
9C000
stack
page read and write
478000
unkown
page readonly
19A000
stack
page read and write
222F000
stack
page read and write
595000
heap
page read and write
400000
unkown
page readonly
62C000
heap
page read and write
401000
unkown
page execute read
266E000
stack
page read and write
471000
unkown
page write copy
547000
heap
page read and write
29BE000
stack
page read and write
23AC000
stack
page read and write
720000
heap
page read and write
400000
unkown
page readonly
401000
unkown
page execute read
1F0000
heap
page read and write
5DE000
stack
page read and write
478000
unkown
page readonly
401000
unkown
page execute read
2D3C000
stack
page read and write
478000
unkown
page readonly
4D0000
heap
page read and write
400000
unkown
page readonly
510000
heap
page read and write
9C000
stack
page read and write
19D000
stack
page read and write
There are 137 hidden memdumps, click here to show them.