IOC Report
tu.exe

loading gif

Files

File Path
Type
Category
Malicious
tu.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\ProgramData\remcos\logs.dat
data
dropped
malicious
C:\Users\user\Documents\ChromeUpdate\SentinelOne.exe
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\8HXJSKQQ\json[1].json
JSON data
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\tu.exe
"C:\Users\user\Desktop\tu.exe"
malicious
C:\Users\user\Desktop\tu.exe
"C:\Users\user\Desktop\tu.exe"
malicious

URLs

Name
IP
Malicious
http://geoplugin.net/json.gp
178.237.33.50
malicious
http://geoplugin.net/json.gp/C
unknown
malicious
abril18.con-ip.com
malicious
http://down.360safe.com/setup.exeIsBetaVersion360ver.dllSOFTWARE
unknown
http://crl.godaddy.com/gdroot-g2.crl0F
unknown
http://geoplugin.net/json.gpalF
unknown
http://crl.godaddy.com/gdig2s5-6.crl0
unknown
http://down.360safe.com/setup.exehttp://down.360safe.com/setupbeta.exe
unknown
http://geoplugin.net/
unknown
http://geoplugin.net/json.gpl
unknown
http://geoplugin.net/json.gpK
unknown
http://certificates.godaddy.com/repository/0
unknown
http://geoplugin.net/json.gpJ
unknown
http://certs.godaddy.com/repository/1301
unknown
http://geoplugin.net/json.gpT
unknown
http://geoplugin.net/json.gpQ
unknown
http://down.360safe.com/360zip_setup.exe360SysReset
unknown
https://certs.godaddy.com/repository/0
unknown
http://.inihttps://map/set
unknown
http://certificates.godaddy.com/repository/gdig2.crt0
unknown
http://geoplugin.net/json.gpSystem32
unknown
http://geoplugin.net/;
unknown
There are 12 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
abril18.con-ip.com
179.14.10.110
malicious
geoplugin.net
178.237.33.50

IPs

IP
Domain
Country
Malicious
179.14.10.110
abril18.con-ip.com
Colombia
malicious
178.237.33.50
geoplugin.net
Netherlands

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
SentinelOneIsCrap
HKEY_CURRENT_USER\SOFTWARE\Rmc-PO8SC5
exepath
HKEY_CURRENT_USER\SOFTWARE\Rmc-PO8SC5
licence
HKEY_CURRENT_USER\SOFTWARE\Rmc-PO8SC5
time

Memdumps

Base Address
Regiontype
Protect
Malicious
937000
heap
page read and write
malicious
8F8000
heap
page read and write
malicious
550000
remote allocation
page execute and read and write
malicious
24CF000
stack
page read and write
malicious
23C0000
direct allocation
page execute and read and write
malicious
46D000
unkown
page execute and read and write
malicious
27BE000
stack
page read and write
4E7000
unkown
page readonly
339F000
stack
page read and write
400000
unkown
page readonly
96C000
heap
page read and write
267C000
stack
page read and write
97A000
heap
page read and write
400000
unkown
page readonly
46D000
unkown
page readonly
401000
unkown
page execute read
29FF000
stack
page read and write
5D0000
heap
page read and write
8F0000
heap
page read and write
99F000
stack
page read and write
77E000
stack
page read and write
97A000
heap
page read and write
5C4000
remote allocation
page execute and read and write
7AA000
heap
page read and write
46D000
unkown
page readonly
7DE000
heap
page read and write
9B000
stack
page read and write
8D0000
heap
page read and write
45C000
unkown
page readonly
BEF000
stack
page read and write
B9F000
stack
page read and write
401000
unkown
page execute read
28BF000
stack
page read and write
263F000
stack
page read and write
5AE000
stack
page read and write
2572000
direct allocation
page read and write
277F000
stack
page read and write
5C8000
remote allocation
page execute and read and write
780000
heap
page read and write
7CE000
heap
page read and write
A9F000
stack
page read and write
46D000
unkown
page readonly
5D5000
heap
page read and write
61C000
stack
page read and write
953000
heap
page read and write
928000
heap
page read and write
467000
unkown
page read and write
71C000
stack
page read and write
45C000
unkown
page readonly
9F0000
heap
page read and write
468000
unkown
page write copy
7AE000
heap
page read and write
7CD000
heap
page read and write
250C000
stack
page read and write
400000
unkown
page readonly
401000
unkown
page execute read
7D3000
heap
page read and write
7D2000
heap
page read and write
7B5000
heap
page read and write
972000
heap
page read and write
196000
stack
page read and write
7CE000
heap
page read and write
972000
heap
page read and write
953000
heap
page read and write
400000
unkown
page readonly
467000
unkown
page write copy
2589000
direct allocation
page read and write
45C000
unkown
page readonly
467000
unkown
page write copy
550000
heap
page read and write
2490000
direct allocation
page read and write
7DF000
heap
page read and write
2438000
direct allocation
page execute and read and write
2480000
heap
page read and write
401000
unkown
page execute read
45C000
unkown
page readonly
7D2000
heap
page read and write
740000
heap
page read and write
28FE000
stack
page read and write
96A000
heap
page read and write
730000
heap
page read and write
467000
unkown
page write copy
972000
heap
page read and write
7B0000
heap
page read and write
7A0000
heap
page read and write
97A000
heap
page read and write
937000
heap
page read and write
2530000
heap
page read and write
A00000
heap
page read and write
6EE000
stack
page read and write
72E000
stack
page read and write
23B0000
heap
page read and write
23CE000
stack
page read and write
7D2000
heap
page read and write
560000
heap
page read and write
329E000
stack
page read and write
There are 86 hidden memdumps, click here to show them.