IOC Report
nvtoaowsdkrthja.exe

loading gif

Files

File Path
Type
Category
Malicious
nvtoaowsdkrthja.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\W1DLB4AP\json[1].json
JSON data
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\nvtoaowsdkrthja.exe
"C:\Users\user\Desktop\nvtoaowsdkrthja.exe"
malicious

URLs

Name
IP
Malicious
angel234se94.ru
malicious
angela2qwdw394.ru
malicious
angeladwedwefds94.ru
malicious
angelasdw12394.ru
malicious
angeladwqwe94.ru
malicious
angela2q32fds94.ru
malicious
http://geoplugin.net/json.gp
178.237.33.50
http://geoplugin.net/json.gpA
unknown
http://geoplugin.net/json.gpg
unknown
http://geoplugin.net/
unknown
http://geoplugin.net/json.gp/C
unknown
http://geoplugin.net/json.gps
unknown
http://geoplugin.net/json.gpSystem32
unknown
http://geoplugin.net/json.gp?
unknown
http://geoplugin.net/json.gp~
unknown
There are 5 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
geoplugin.net
178.237.33.50

IPs

IP
Domain
Country
Malicious
193.124.47.250
unknown
Russian Federation
malicious
178.237.33.50
geoplugin.net
Netherlands

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\SOFTWARE\ -TEM3DH
licence
HKEY_CURRENT_USER\SOFTWARE\ -TEM3DH
time
HKEY_CURRENT_USER\SOFTWARE\ -TEM3DH
UID

Memdumps

Base Address
Regiontype
Protect
Malicious
44D000
unkown
page readonly
malicious
44D000
unkown
page readonly
malicious
4C0000
heap
page read and write
6C0000
heap
page read and write
6CE000
heap
page read and write
65E000
stack
page read and write
2D1F000
stack
page read and write
738000
heap
page read and write
69E000
stack
page read and write
480000
heap
page read and write
2310000
heap
page read and write
19D000
stack
page read and write
701000
heap
page read and write
241F000
stack
page read and write
467000
unkown
page read and write
727000
heap
page read and write
1F0000
heap
page read and write
46B000
unkown
page readonly
73A000
heap
page read and write
742000
heap
page read and write
9C000
stack
page read and write
701000
heap
page read and write
225F000
stack
page read and write
4A0000
heap
page read and write
6CA000
heap
page read and write
2C1E000
stack
page read and write
46B000
unkown
page readonly
401000
unkown
page execute read
4C5000
heap
page read and write
742000
heap
page read and write
464000
unkown
page write copy
400000
unkown
page readonly
400000
unkown
page readonly
727000
heap
page read and write
464000
unkown
page read and write
401000
unkown
page execute read
7D0000
heap
page read and write
7C0000
heap
page read and write
742000
heap
page read and write
There are 29 hidden memdumps, click here to show them.