IOC Report
xi0TpAxHGMsm.exe

loading gif

Files

File Path
Type
Category
Malicious
xi0TpAxHGMsm.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\ProgramData\Disk\Disk.dat
data
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\BEDT2L3A\json[1].json
JSON data
dropped
C:\Users\user\AppData\Local\Temp\yghndvikdwwpc.vbs
data
modified

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\xi0TpAxHGMsm.exe
"C:\Users\user\Desktop\xi0TpAxHGMsm.exe"
malicious
C:\Windows\SysWOW64\wscript.exe
"C:\Windows\System32\WScript.exe" "C:\Users\user~1\AppData\Local\Temp\yghndvikdwwpc.vbs"
malicious

URLs

Name
IP
Malicious
http://geoplugin.net/json.gp
178.237.33.50
malicious
sendfiletiahforem.duckdns.org
malicious
http://geoplugin.net/json.gp/C
unknown
malicious
http://geoplugin.net/json.gpT
unknown
http://geoplugin.net/json.gp7
unknown
http://geoplugin.net/json.gpI
unknown
http://geoplugin.net/json.gpSystem32
unknown
http://geoplugin.net/json.gpN
unknown
http://geoplugin.net/json.gp-
unknown

Domains

Name
IP
Malicious
sendfiletiahforem.duckdns.org
85.60.29.68
malicious
geoplugin.net
178.237.33.50

IPs

IP
Domain
Country
Malicious
85.60.29.68
sendfiletiahforem.duckdns.org
Spain
malicious
178.237.33.50
geoplugin.net
Netherlands

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\SOFTWARE\Rmc-4QQORA
exepath
malicious
HKEY_CURRENT_USER\SOFTWARE\Rmc-4QQORA
licence
malicious
HKEY_CURRENT_USER\SOFTWARE\Rmc-4QQORA
time
malicious
HKEY_CURRENT_USER_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
LangID
HKEY_CURRENT_USER_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
C:\Windows\System32\WScript.exe.FriendlyAppName
HKEY_CURRENT_USER_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
C:\Windows\System32\WScript.exe.ApplicationCompany

Memdumps

Base Address
Regiontype
Protect
Malicious
459000
unkown
page readonly
malicious
69E000
heap
page read and write
malicious
459000
unkown
page readonly
malicious
400000
unkown
page readonly
70F000
heap
page read and write
394F000
stack
page read and write
471000
unkown
page read and write
395C000
heap
page read and write
AE7000
heap
page read and write
216C000
stack
page read and write
AE6000
heap
page read and write
660000
heap
page read and write
B05000
heap
page read and write
702000
heap
page read and write
AD1000
heap
page read and write
718000
heap
page read and write
AFB000
heap
page read and write
AA8000
heap
page read and write
3C0C000
stack
page read and write
718000
heap
page read and write
70F000
heap
page read and write
AE1000
heap
page read and write
6CD000
heap
page read and write
2E70000
heap
page read and write
4872000
heap
page read and write
710000
heap
page read and write
6DD000
heap
page read and write
AFE000
heap
page read and write
718000
heap
page read and write
A98000
heap
page read and write
6DD000
heap
page read and write
ACE000
heap
page read and write
70F000
heap
page read and write
A30000
heap
page read and write
B04000
heap
page read and write
AB8000
heap
page read and write
718000
heap
page read and write
BC5000
heap
page read and write
5DE000
stack
page read and write
3956000
heap
page read and write
ADD000
heap
page read and write
7CB000
stack
page read and write
AF7000
heap
page read and write
728000
heap
page read and write
B00000
heap
page read and write
3700000
heap
page read and write
702000
heap
page read and write
4875000
heap
page read and write
355C000
stack
page read and write
AD7000
heap
page read and write
725000
heap
page read and write
4D90000
heap
page read and write
1F0000
heap
page read and write
4D90000
heap
page read and write
2C0E000
stack
page read and write
702000
heap
page read and write
AF7000
heap
page read and write
AD6000
heap
page read and write
278C000
stack
page read and write
AD1000
heap
page read and write
728000
heap
page read and write
AF5000
heap
page read and write
718000
heap
page read and write
702000
heap
page read and write
4D81000
heap
page read and write
711000
heap
page read and write
718000
heap
page read and write
AD1000
heap
page read and write
ADB000
heap
page read and write
702000
heap
page read and write
702000
heap
page read and write
AF0000
heap
page read and write
AD6000
heap
page read and write
3E56000
heap
page read and write
3D0D000
stack
page read and write
58A5000
heap
page read and write
69A000
heap
page read and write
711000
heap
page read and write
6CD000
heap
page read and write
702000
heap
page read and write
725000
heap
page read and write
AE1000
heap
page read and write
22CF000
stack
page read and write
AE3000
heap
page read and write
AB8000
heap
page read and write
36FC000
stack
page read and write
702000
heap
page read and write
2D0F000
stack
page read and write
725000
heap
page read and write
B04000
heap
page read and write
274F000
stack
page read and write
6DD000
heap
page read and write
AC1000
heap
page read and write
595000
heap
page read and write
AD4000
heap
page read and write
4D0E000
stack
page read and write
383E000
stack
page read and write
4D90000
heap
page read and write
6DD000
heap
page read and write
398C000
stack
page read and write
4F4F000
stack
page read and write
373B000
heap
page read and write
264E000
stack
page read and write
36BC000
stack
page read and write
3A8B000
stack
page read and write
5395000
heap
page read and write
2EF0000
heap
page read and write
AF4000
heap
page read and write
288F000
stack
page read and write
ACB000
heap
page read and write
30FF000
stack
page read and write
2E3E000
stack
page read and write
AE9000
heap
page read and write
ADC000
heap
page read and write
A7E000
stack
page read and write
6D4000
heap
page read and write
337E000
stack
page read and write
6CD000
heap
page read and write
4D80000
heap
page read and write
4D90000
heap
page read and write
478000
unkown
page readonly
2E4F000
stack
page read and write
250E000
stack
page read and write
AFF000
heap
page read and write
A80000
heap
page read and write
21AC000
stack
page read and write
401000
unkown
page execute read
3730000
heap
page read and write
AE4000
heap
page read and write
AC1000
heap
page read and write
2D4E000
stack
page read and write
2E8E000
stack
page read and write
718000
heap
page read and write
4D81000
heap
page read and write
9C000
stack
page read and write
711000
heap
page read and write
260F000
stack
page read and write
711000
heap
page read and write
D9E000
stack
page read and write
4E8A000
heap
page read and write
AF9000
heap
page read and write
70F000
heap
page read and write
24CF000
stack
page read and write
560000
heap
page read and write
AC1000
heap
page read and write
4365000
heap
page read and write
6DD000
heap
page read and write
65E000
stack
page read and write
4E0F000
stack
page read and write
710000
heap
page read and write
61E000
stack
page read and write
AD1000
heap
page read and write
6CB000
stack
page read and write
AFF000
heap
page read and write
4D81000
heap
page read and write
ADE000
heap
page read and write
AED000
heap
page read and write
AD1000
heap
page read and write
98F000
stack
page read and write
AF3000
heap
page read and write
ACF000
heap
page read and write
AB8000
heap
page read and write
6EDF1000
unkown
page execute read
AEC000
heap
page read and write
AE7000
heap
page read and write
2FFE000
stack
page read and write
702000
heap
page read and write
6DD000
heap
page read and write
471000
unkown
page write copy
AFF000
heap
page read and write
725000
heap
page read and write
6EDF0000
unkown
page readonly
AE3000
heap
page read and write
3840000
heap
page read and write
AF8000
heap
page read and write
718000
heap
page read and write
AF5000
heap
page read and write
436A000
heap
page read and write
ACD000
heap
page read and write
AE1000
heap
page read and write
2EFA000
heap
page read and write
6DD000
heap
page read and write
AE3000
heap
page read and write
479E000
stack
page read and write
3952000
heap
page read and write
AE5000
heap
page read and write
6CD000
heap
page read and write
34BB000
stack
page read and write
718000
heap
page read and write
327E000
stack
page read and write
19C000
stack
page read and write
AFB000
heap
page read and write
6EE06000
unkown
page readonly
6EE0D000
unkown
page read and write
AC0000
heap
page read and write
B03000
heap
page read and write
6CD000
heap
page read and write
2E50000
heap
page read and write
718000
heap
page read and write
A90000
heap
page read and write
725000
heap
page read and write
AD2000
heap
page read and write
AA5000
heap
page read and write
323E000
stack
page read and write
33BE000
stack
page read and write
313E000
stack
page read and write
474000
unkown
page read and write
AEB000
heap
page read and write
B03000
heap
page read and write
4D90000
heap
page read and write
AE3000
heap
page read and write
AE9000
heap
page read and write
401000
unkown
page execute read
478000
unkown
page readonly
718000
heap
page read and write
6EE0F000
unkown
page readonly
4F50000
heap
page read and write
2F8F000
stack
page read and write
590000
heap
page read and write
6DD000
heap
page read and write
AF5000
heap
page read and write
690000
heap
page read and write
4E4E000
stack
page read and write
88E000
stack
page read and write
365E000
stack
page read and write
6DD000
heap
page read and write
AFE000
heap
page read and write
AE5000
heap
page read and write
21C7000
heap
page read and write
BC0000
heap
page read and write
23CF000
stack
page read and write
718000
heap
page read and write
400000
unkown
page readonly
702000
heap
page read and write
718000
heap
page read and write
AD9000
heap
page read and write
21C0000
heap
page read and write
3E52000
heap
page read and write
72A000
heap
page read and write
There are 229 hidden memdumps, click here to show them.