IOC Report
1713934625194381993b7036c2f81df0c4f94527f4e7bb43abdf90d09e24f7ee13cf33c8d8678.dat-decoded.exe

loading gif

Files

File Path
Type
Category
Malicious
1713934625194381993b7036c2f81df0c4f94527f4e7bb43abdf90d09e24f7ee13cf33c8d8678.dat-decoded.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\ProgramData\remcos\logs.dat
data
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WDKI0JR2\json[1].json
JSON data
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\1713934625194381993b7036c2f81df0c4f94527f4e7bb43abdf90d09e24f7ee13cf33c8d8678.dat-decoded.exe
"C:\Users\user\Desktop\1713934625194381993b7036c2f81df0c4f94527f4e7bb43abdf90d09e24f7ee13cf33c8d8678.dat-decoded.exe"
malicious

URLs

Name
IP
Malicious
http://geoplugin.net/json.gp
178.237.33.50
malicious
jimbb.ydns.eu
malicious
http://geoplugin.net/json.gp/C
unknown
malicious
http://geoplugin.net/json.gp4
unknown
http://geoplugin.net/json.gpD
unknown
http://geoplugin.net/json.gpF
unknown
http://geoplugin.net/
unknown
http://geoplugin.net/json.gpl
unknown
http://geoplugin.net/json.gpK
unknown
http://geoplugin.net/json.gpZ
unknown
http://geoplugin.net/json.gpSystem32
unknown
There are 1 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
jimbb.ydns.eu
23.226.132.239
malicious
geoplugin.net
178.237.33.50

IPs

IP
Domain
Country
Malicious
23.226.132.239
jimbb.ydns.eu
United States
malicious
178.237.33.50
geoplugin.net
Netherlands

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\SOFTWARE\Rmcerytuyiuoio-2AOB3L
exepath
HKEY_CURRENT_USER\SOFTWARE\Rmcerytuyiuoio-2AOB3L
licence
HKEY_CURRENT_USER\SOFTWARE\Rmcerytuyiuoio-2AOB3L
time

Memdumps

Base Address
Regiontype
Protect
Malicious
4BE000
heap
page read and write
malicious
232F000
stack
page read and write
malicious
459000
unkown
page readonly
malicious
459000
unkown
page readonly
malicious
401000
unkown
page execute read
23D0000
heap
page read and write
4F1000
heap
page read and write
680000
heap
page read and write
4B0000
heap
page read and write
25DF000
stack
page read and write
1E0000
heap
page read and write
517000
heap
page read and write
4A0000
heap
page read and write
23B0000
heap
page read and write
542000
heap
page read and write
222E000
stack
page read and write
401000
unkown
page execute read
236C000
stack
page read and write
531000
heap
page read and write
539000
heap
page read and write
539000
heap
page read and write
540000
heap
page read and write
285F000
stack
page read and write
313E000
stack
page read and write
517000
heap
page read and write
23AC000
stack
page read and write
54D000
heap
page read and write
9C000
stack
page read and write
4BA000
heap
page read and write
271F000
stack
page read and write
542000
heap
page read and write
8BF000
stack
page read and write
539000
heap
page read and write
54D000
heap
page read and write
490000
heap
page read and write
478000
unkown
page readonly
471000
unkown
page write copy
474000
unkown
page read and write
544000
heap
page read and write
542000
heap
page read and write
523000
heap
page read and write
500000
heap
page read and write
24DF000
stack
page read and write
261E000
stack
page read and write
54E000
heap
page read and write
400000
unkown
page readonly
540000
heap
page read and write
478000
unkown
page readonly
1E7000
heap
page read and write
523000
heap
page read and write
323F000
stack
page read and write
471000
unkown
page read and write
19C000
stack
page read and write
544000
heap
page read and write
400000
unkown
page readonly
540000
heap
page read and write
275E000
stack
page read and write
500000
heap
page read and write
533000
heap
page read and write
7BE000
stack
page read and write
544000
heap
page read and write
There are 51 hidden memdumps, click here to show them.