IOC Report
MT Marine Tiger.exe

loading gif

Files

File Path
Type
Category
Malicious
MT Marine Tiger.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\MT Marine Tiger.exe.log
ASCII text, with CRLF line terminators
dropped
malicious

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\MT Marine Tiger.exe
"C:\Users\user\Desktop\MT Marine Tiger.exe"
malicious
C:\Users\user\Desktop\MT Marine Tiger.exe
"C:\Users\user\Desktop\MT Marine Tiger.exe"
malicious

URLs

Name
IP
Malicious
https://reallyfreegeoip.org
unknown
http://checkip.dyndns.org
unknown
http://checkip.dyndns.org/
132.226.8.169
http://checkip.dyndns.com
unknown
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
unknown
https://reallyfreegeoip.org/xml/173.254.250.91$
unknown
http://103.130.147.85
unknown
http://checkip.dyndns.org/q
unknown
https://reallyfreegeoip.org/xml/173.254.250.91
188.114.97.3
http://reallyfreegeoip.org
unknown
https://reallyfreegeoip.org/xml/
unknown
There are 1 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
reallyfreegeoip.org
188.114.97.3
malicious
checkip.dyndns.org
unknown
malicious
checkip.dyndns.com
132.226.8.169

IPs

IP
Domain
Country
Malicious
188.114.97.3
reallyfreegeoip.org
European Union
malicious
132.226.8.169
checkip.dyndns.com
United States

Registry

Path
Value
Malicious
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\MT Marine Tiger_RASAPI32
EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\MT Marine Tiger_RASAPI32
EnableAutoFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\MT Marine Tiger_RASAPI32
EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\MT Marine Tiger_RASAPI32
FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\MT Marine Tiger_RASAPI32
ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\MT Marine Tiger_RASAPI32
MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\MT Marine Tiger_RASAPI32
FileDirectory
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\MT Marine Tiger_RASMANCS
EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\MT Marine Tiger_RASMANCS
EnableAutoFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\MT Marine Tiger_RASMANCS
EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\MT Marine Tiger_RASMANCS
FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\MT Marine Tiger_RASMANCS
ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\MT Marine Tiger_RASMANCS
MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\MT Marine Tiger_RASMANCS
FileDirectory
There are 4 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
2841000
trusted library allocation
page read and write
malicious
812000
remote allocation
page execute and read and write
malicious
3C79000
trusted library allocation
page read and write
malicious
2A08000
trusted library allocation
page read and write
malicious
5D5D000
heap
page read and write
2C60000
heap
page execute and read and write
521F000
trusted library allocation
page read and write
761E000
stack
page read and write
4E60000
heap
page read and write
C53000
trusted library allocation
page execute and read and write
4D10000
trusted library allocation
page read and write
6490000
trusted library allocation
page read and write
5640000
trusted library allocation
page read and write
5650000
trusted library allocation
page read and write
2ADE000
stack
page read and write
4E5F000
trusted library allocation
page read and write
5D7D000
heap
page read and write
1250000
trusted library allocation
page read and write
D80000
heap
page read and write
54D0000
trusted library allocation
page read and write
262E000
trusted library allocation
page read and write
739E000
stack
page read and write
29F2000
trusted library allocation
page read and write
C82000
trusted library allocation
page read and write
2C40000
trusted library allocation
page read and write
29A8000
trusted library allocation
page read and write
29D1000
trusted library allocation
page read and write
5171000
trusted library allocation
page read and write
4D18000
trusted library allocation
page read and write
263E000
trusted library allocation
page read and write
601E000
stack
page read and write
64A0000
trusted library allocation
page read and write
516E000
trusted library allocation
page read and write
C50000
trusted library allocation
page read and write
8BE000
stack
page read and write
2C55000
trusted library allocation
page read and write
C7A000
trusted library allocation
page execute and read and write
1282000
trusted library allocation
page read and write
54E9000
trusted library allocation
page read and write
8C0000
heap
page read and write
56C0000
heap
page read and write
4E5A000
trusted library allocation
page read and write
4C80000
trusted library allocation
page read and write
614D000
stack
page read and write
6020000
heap
page read and write
2A76000
trusted library allocation
page read and write
54EE000
trusted library allocation
page read and write
1263000
trusted library allocation
page execute and read and write
8E0000
heap
page read and write
1264000
trusted library allocation
page read and write