IOC Report
5046511eb489387b7a835a990ea3b36b77185f3fad905511c4bce30aa654c60b_dump.exe

loading gif

Files

File Path
Type
Category
Malicious
5046511eb489387b7a835a990ea3b36b77185f3fad905511c4bce30aa654c60b_dump.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Roaming\loggsdSSC\logs.dat
data
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3D003UC5\json[1].json
JSON data
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\5046511eb489387b7a835a990ea3b36b77185f3fad905511c4bce30aa654c60b_dump.exe
"C:\Users\user\Desktop\5046511eb489387b7a835a990ea3b36b77185f3fad905511c4bce30aa654c60b_dump.exe"
malicious

URLs

Name
IP
Malicious
areaseguras.con-ip.com
malicious
http://geoplugin.net/json.gp
178.237.33.50
http://geoplugin.net/
unknown
http://geoplugin.net/json.gp/C
unknown
http://geoplugin.net/json.gp=Q
unknown
http://geoplugin.net/json.gpSystem32
unknown
http://geoplugin.net/json.gp6fgQ
unknown

Domains

Name
IP
Malicious
areaseguras.con-ip.com
86.104.72.183
malicious
198.187.3.20.in-addr.arpa
unknown
malicious
geoplugin.net
178.237.33.50

IPs

IP
Domain
Country
Malicious
86.104.72.183
areaseguras.con-ip.com
Romania
malicious
178.237.33.50
geoplugin.net
Netherlands

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\SOFTWARE\Rmc121455011-7TOVMS
exepath
HKEY_CURRENT_USER\SOFTWARE\Rmc121455011-7TOVMS
licence
HKEY_CURRENT_USER\SOFTWARE\Rmc121455011-7TOVMS
time

Memdumps

Base Address
Regiontype
Protect
Malicious
459000
unkown
page readonly
malicious
5FE000
heap
page read and write
malicious
459000
unkown
page readonly
malicious
490000
heap
page read and write
670000
heap
page read and write
471000
unkown
page write copy
2FEE000
stack
page read and write
4DE000
stack
page read and write
641000
heap
page read and write
2270000
heap
page read and write
401000
unkown
page execute read
263E000
stack
page read and write
400000
unkown
page readonly
9C000
stack
page read and write
5F0000
heap
page read and write
5FA000
heap
page read and write
57E000
stack
page read and write
674000
heap
page read and write
67B000
heap
page read and write
400000
unkown
page readonly
662000
heap
page read and write
30EF000
stack
page read and write
471000
unkown
page read and write
631000
heap
page read and write
67B000
heap
page read and write
24BF000
stack
page read and write
9BF000
stack
page read and write
662000
heap
page read and write
7C0000
heap
page read and write
537000
heap
page read and write
67B000
heap
page read and write
5C0000
heap
page read and write
225F000
stack
page read and write
25FF000
stack
page read and write
24FE000
stack
page read and write
5BC000
stack
page read and write
530000
heap
page read and write
273F000
stack
page read and write
670000
heap
page read and write
478000
unkown
page readonly
19C000
stack
page read and write
1F0000
heap
page read and write
641000
heap
page read and write
23BC000
stack
page read and write
474000
unkown
page read and write
478000
unkown
page readonly
673000
heap
page read and write
401000
unkown
page execute read
237F000
stack
page read and write
There are 39 hidden memdumps, click here to show them.