Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
tu.exe
|
PE32 executable (GUI) Intel 80386, for MS Windows
|
initial sample
|
||
C:\ProgramData\remcos\logs.dat
|
data
|
dropped
|
||
C:\Users\user\Documents\ChromeUpdate\SentinelOne.exe
|
PE32 executable (GUI) Intel 80386, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\8HXJSKQQ\json[1].json
|
JSON data
|
dropped
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\tu.exe
|
"C:\Users\user\Desktop\tu.exe"
|
||
C:\Users\user\Desktop\tu.exe
|
"C:\Users\user\Desktop\tu.exe"
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://geoplugin.net/json.gp
|
178.237.33.50
|
||
http://geoplugin.net/json.gp/C
|
unknown
|
||
abril18.con-ip.com
|
|||
http://down.360safe.com/setup.exeIsBetaVersion360ver.dllSOFTWARE
|
unknown
|
||
http://crl.godaddy.com/gdroot-g2.crl0F
|
unknown
|
||
http://geoplugin.net/json.gpalF
|
unknown
|
||
http://crl.godaddy.com/gdig2s5-6.crl0
|
unknown
|
||
http://down.360safe.com/setup.exehttp://down.360safe.com/setupbeta.exe
|
unknown
|
||
http://geoplugin.net/
|
unknown
|
||
http://geoplugin.net/json.gpl
|
unknown
|
||
http://geoplugin.net/json.gpK
|
unknown
|
||
http://certificates.godaddy.com/repository/0
|
unknown
|
||
http://geoplugin.net/json.gpJ
|
unknown
|
||
http://certs.godaddy.com/repository/1301
|
unknown
|
||
http://geoplugin.net/json.gpT
|
unknown
|
||
http://geoplugin.net/json.gpQ
|
unknown
|
||
http://down.360safe.com/360zip_setup.exe360SysReset
|
unknown
|
||
https://certs.godaddy.com/repository/0
|
unknown
|
||
http://.inihttps://map/set
|
unknown
|
||
http://certificates.godaddy.com/repository/gdig2.crt0
|
unknown
|
||
http://geoplugin.net/json.gpSystem32
|
unknown
|
||
http://geoplugin.net/;
|
unknown
|
There are 12 hidden URLs, click here to show them.
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
abril18.con-ip.com
|
179.14.10.110
|
||
geoplugin.net
|
178.237.33.50
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
179.14.10.110
|
abril18.con-ip.com
|
Colombia
|
||
178.237.33.50
|
geoplugin.net
|
Netherlands
|
Registry
Path
|
Value
|
Malicious
|
|
---|---|---|---|
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
|
SentinelOneIsCrap
|
||
HKEY_CURRENT_USER\SOFTWARE\Rmc-PO8SC5
|
exepath
|
||
HKEY_CURRENT_USER\SOFTWARE\Rmc-PO8SC5
|
licence
|
||
HKEY_CURRENT_USER\SOFTWARE\Rmc-PO8SC5
|
time
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
937000
|
heap
|
page read and write
|
||
8F8000
|
heap
|
page read and write
|
||
550000
|
remote allocation
|
page execute and read and write
|
||
24CF000
|
stack
|
page read and write
|
||
23C0000
|
direct allocation
|
page execute and read and write
|
||
46D000
|
unkown
|
page execute and read and write
|
||
27BE000
|
stack
|
page read and write
|
||
4E7000
|
unkown
|
page readonly
|
||
339F000
|
stack
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
96C000
|
heap
|
page read and write
|
||
267C000
|
stack
|
page read and write
|
||
97A000
|
heap
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
46D000
|
unkown
|
page readonly
|
||
401000
|
unkown
|
page execute read
|
||
29FF000
|
stack
|
page read and write
|
||
5D0000
|
heap
|
page read and write
|
||
8F0000
|
heap
|
page read and write
|
||
99F000
|
stack
|
page read and write
|
||
77E000
|
stack
|
page read and write
|
||
97A000
|
heap
|
page read and write
|
||
5C4000
|
remote allocation
|
page execute and read and write
|
||
7AA000
|
heap
|
page read and write
|
||
46D000
|
unkown
|
page readonly
|
||
7DE000
|
heap
|
page read and write
|
||
9B000
|
stack
|
page read and write
|
||
8D0000
|
heap
|
page read and write
|
||
45C000
|
unkown
|
page readonly
|
||
BEF000
|
stack
|
page read and write
|
||
B9F000
|
stack
|
page read and write
|
||
401000
|
unkown
|
page execute read
|
||
28BF000
|
stack
|
page read and write
|
||
263F000
|
stack
|
page read and write
|
||
5AE000
|
stack
|
page read and write
|
||
2572000
|
direct allocation
|
page read and write
|
||
277F000
|
stack
|
page read and write
|
||
5C8000
|
remote allocation
|
page execute and read and write
|
||
780000
|
heap
|
page read and write
|
||
7CE000
|
heap
|
page read and write
|
||
A9F000
|
stack
|
page read and write
|
||
46D000
|
unkown
|
page readonly
|
||
5D5000
|
heap
|
page read and write
|
||
61C000
|
stack
|
page read and write
|
||
953000
|
heap
|
page read and write
|
||
928000
|
heap
|
page read and write
|
||
467000
|
unkown
|
page read and write
|
||
71C000
|
stack
|
page read and write
|
||
45C000
|
unkown
|
page readonly
|
||
9F0000
|
heap
|
page read and write
|
||
468000
|
unkown
|
page write copy
|
||
7AE000
|
heap
|
page read and write
|
||
7CD000
|
heap
|
page read and write
|
||
250C000
|
stack
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
401000
|
unkown
|
page execute read
|
||
7D3000
|
heap
|
page read and write
|
||
7D2000
|
heap
|
page read and write
|
||
7B5000
|
heap
|
page read and write
|
||
972000
|
heap
|
page read and write
|
||
196000
|
stack
|
page read and write
|
||
7CE000
|
heap
|
page read and write
|
||
972000
|
heap
|
page read and write
|
||
953000
|
heap
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
467000
|
unkown
|
page write copy
|
||
2589000
|
direct allocation
|
page read and write
|
||
45C000
|
unkown
|
page readonly
|
||
467000
|
unkown
|
page write copy
|
||
550000
|
heap
|
page read and write
|
||
2490000
|
direct allocation
|
page read and write
|
||
7DF000
|
heap
|
page read and write
|
||
2438000
|
direct allocation
|
page execute and read and write
|
||
2480000
|
heap
|
page read and write
|
||
401000
|
unkown
|
page execute read
|
||
45C000
|
unkown
|
page readonly
|
||
7D2000
|
heap
|
page read and write
|
||
740000
|
heap
|
page read and write
|
||
28FE000
|
stack
|
page read and write
|
||
96A000
|
heap
|
page read and write
|
||
730000
|
heap
|
page read and write
|
||
467000
|
unkown
|
page write copy
|
||
972000
|
heap
|
page read and write
|
||
7B0000
|
heap
|
page read and write
|
||
7A0000
|
heap
|
page read and write
|
||
97A000
|
heap
|
page read and write
|
||
937000
|
heap
|
page read and write
|
||
2530000
|
heap
|
page read and write
|
||
A00000
|
heap
|
page read and write
|
||
6EE000
|
stack
|
page read and write
|
||
72E000
|
stack
|
page read and write
|
||
23B0000
|
heap
|
page read and write
|
||
23CE000
|
stack
|
page read and write
|
||
7D2000
|
heap
|
page read and write
|
||
560000
|
heap
|
page read and write
|
||
329E000
|
stack
|
page read and write
|
There are 86 hidden memdumps, click here to show them.