IOC Report
file.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\file.exe
"C:\Users\user\Desktop\file.exe"
malicious

URLs

Name
IP
Malicious
https://bathdoomgaz.store:443/api
unknown
malicious
studennotediw.store
malicious
dissapoiznw.store
malicious
https://steamcommunity.com/profiles/76561199724331900
104.102.49.254
malicious
eaglepawnoy.store
malicious
bathdoomgaz.store
malicious
clearancek.site
malicious
spirittunek.store
malicious
licendfilteo.site
malicious
https://player.vimeo.com
unknown
https://steamcommunity.com/?subsection=broadcasts
unknown
https://community.cloudflare.steamstatic.com/public/shared/javascript/shared_global.js?v=wJD9maDpDcV
unknown
https://sergei-esenin.com/
unknown
https://community.cloudflare.steamstatic.com/public/javascript/global.js?v=bOP7RorZq4_W&
unknown
https://store.steampowered.com/subscriber_agreement/
unknown
https://www.gstatic.cn/recaptcha/
unknown
https://community.cloudflare.steamstatic.com/public/javascript/modalContent.js?v=UuGFpt56D9L4&l=
unknown
https://community.cloudflare.steamstatic.com/public/javascript/modalv2.js?v=dfMhuy-Lrpyo&l=engli
unknown
https://community.cloudflare.steamstatic.com/public/javascript/promo/stickers.js?v=GfA42_x2_aub&
unknown
https://community.cloudflare.steamstatic.com/public/javascript/scriptaculous/_combined.js?v=OeNIgrpE
unknown
http://www.valvesoftware.com/legal.htm
unknown
https://community.cloudflare.steamstatic.com/public/css/promo/summer2
unknown
https://licendfilteo.site:443/apii
unknown
https://sergei-esenin.com:443/apiVn
unknown
https://www.youtube.com
unknown
https://www.google.com
unknown
https://www.valvesoftware.com/en/contact?contact-person=Translation%20Team%20Feedback
unknown
https://s.ytimg.com;
unknown
https://steam.tv/
unknown
https://community.cloudflare.steamstatic.com/public/javascript/applications/community/main.js?v=W9BX
unknown
https://community.cloudflare.steamstatic.com/public/javascript/prototype-1.7.js?v=.55t44gwuwgvw&
unknown
http://store.steampowered.com/privacy_agreement/
unknown
https://community.cloudflare.steamstatic.com/public/shared/css/shared_responsive.css?v=eghn9DNyCY67&
unknown
https://store.steampowered.com/points/shop/
unknown
https://community.cloudflare.steamstatic.com/public/css/promo/summer2017/stickers.css?v=bZKSp7oNwVPK
unknown
https://community.cloudflare.steamstatic.com/public/javascript/reportedcontent.js?v=dAtjbcZMWhSe&amp
unknown
https://community.cloudflare.steamstatic.com/public/css/skin_1/modalContent.css?v=.VpiwkLAYt9r1&
unknown
https://sketchfab.com
unknown
https://lv.queniujq.cn
unknown
https://steamcommunity.com/profiles/76561199724331900/inventory/
unknown
https://www.youtube.com/
unknown
https://store.steampowered.com/privacy_agreement/
unknown
https://cdn.cloudflare.steamstatic.com/steamcommunity/public/assets/
unknown
https://community.cloudflare.steamstatic.com/public/javascript/webui/clientcom.js?v=qYlgdgWOD4Ng&amp
unknown
https://community.cloudflare.steamstatic.com/public/shared/images/responsive/logo_valve_footer.png
unknown
https://community.cloudflare.steamstatic.com/public/shared/images/header/logo_steam.svg?t=962016
unknown
https://www.google.com/recaptcha/
unknown
https://checkout.steampowered.com/
unknown
https://community.cloudflare.steamstatic.com/public/javascript/promo/sticker
unknown
https://community.cloudflare.steamstatic.com/public/javascript/applications/community/libraries~b28b
unknown
https://community.cloudflare.steamstatic.com/public/shared/images/responsive/header_logo.png
unknown
https://sergei-esenin.com/apip
unknown
https://sergei-esenin.com/M
unknown
https://store.steampowered.com/;
unknown
https://community.cloudflare.steamstatic.com/public/javascript/profile.js?v=KkhJqW2NGKiM&l=engli
unknown
https://store.steampowered.com/about/
unknown
https://community.cloudflare.steamstatic.com/
unknown
https://steamcommunity.com/my/wishlist/
unknown
https://community.cloudflare.st
unknown
https://avatars.cloudflare.steamstatic.com/fef49e7fa7e1997310d705b2a6158ff8d
unknown
https://community.cloudflare.steamstatic.com/public/javascript/jquery-1.11.1.min.js?v=.isFTSRckeNhC&
unknown
https://help.steampowered.com/en/
unknown
https://steamcommunity.com/market/
unknown
https://store.steampowered.com/news/
unknown
https://community.cloudflare.steamstatic.com/public/javascript/global.js?v=b
unknown
https://sergei-esenin.com/5
unknown
http://store.steampowered.com/subscriber_agreement/
unknown
https://community.cloudflare.steamstatic.com/public/javascript/applications/community/manifest.js?v=
unknown
https://steamcommunity.com/linkfilter/?u=http%3A%2F%2Fwww.geonames.org
unknown
https://community.cloudflare.steamstatic.com/public/css/applications/community/main.css?v=ljhW-PbGuX
unknown
https://recaptcha.net/recaptcha/;
unknown
https://steamcommunity.com/discussions/
unknown
https://store.steampowered.com/stats/
unknown
https://community.cloudflare.steamstatic.com/public/javascript/global.js?v=bOP7RorZq4_W&l=englis
unknown
https://medal.tv
unknown
https://broadcast.st.dl.eccdnx.com
unknown
https://community.cloudflare.steamstatic.com/public/shared/javascript/tooltip.js?v=.zYHOpI1L3Rt0&amp
unknown
https://store.steampowered.com/steam_refunds/
unknown
https://community.cloudflare.steamstatic.com/public/images/skin_1/arrowDn9x5.gif
unknown
https://community.cloudflare.steamstatic.com/public/shared/javascript/shared_responsive_adapter.js?v
unknown
https://community.cloudflare.steamstatic.com/public/shared/images/responsive/header_menu_hamburger.p
unknown
https://steamcommunity.com/login/home/?goto=profiles%2F76561199724331900
unknown
https://steamcommunity.com/profiles/76561199724331900jA5Y
unknown
https://community.cloudflare.steamstatic.com/public/shared/javascript/auth_refresh.js?v=WgUxSlKTb3W1
unknown
https://steamcommunity.com/workshop/
unknown
https://login.steampowered.com/
unknown
https://store.steampowered.com/legal/
unknown
https://sergei-esenin.com/api5
unknown
https://community.cloudflare.steamstatic.com/public/shared/css/buttons.css?v=tuNiaSwXwcYT&l=engl
unknown
https://community.cloudflare.steamstatic.com/public/shared/css/motiva_sans.css?v=GfSjbGKcNYaQ&l=
unknown
https://community.cloudflare.steamstatic.com/public/css/skin_1/profilev2.css?v=gNE3gksLVEVa&l=en
unknown
https://community.cloudflare.steamstatic.com/public/css/globalv2.css?v=pwVcIAtHNXwg&l=english&am
unknown
https://community.cloudflare.steamstatic.com/public/css/skin_1/header.css?v=vh4BMeDcNiCU&l=engli
unknown
https://recaptcha.net
unknown
https://steamcommunity.com:443/profiles/765611997243319005n
unknown
https://store.steampowered.com/
unknown
https://steamcommunity.com
unknown
https://community.cloudflare.steamstatic.com/public/shared/css/shared_global.css?v=Ff_1prscqzeu&
unknown
http://127.0.0.1:27060
unknown
https://community.cloudflare.steamstatic.com/public/images/skin_1/footerLogo_valve.png?v=1
unknown
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
steamcommunity.com
104.102.49.254
malicious
eaglepawnoy.store
unknown
malicious
bathdoomgaz.store
unknown
malicious
spirittunek.store
unknown
malicious
licendfilteo.site
unknown
malicious
studennotediw.store
unknown
malicious
mobbipenju.store
unknown
malicious
clearancek.site
unknown
malicious
dissapoiznw.store
unknown
malicious
sergei-esenin.com
unknown

IPs

IP
Domain
Country
Malicious
104.102.49.254
steamcommunity.com
United States
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
AC1000
unkown
page execute and read and write
malicious
53BE000
stack
page read and write
D8F000
unkown
page execute and read and write
4C50000
heap
page read and write
CA2000
unkown
page execute and read and write
324F000
stack
page read and write
B20000
unkown
page execute and write copy
D65000
unkown
page execute and read and write
3FCF000
stack
page read and write
2F30000
direct allocation
page read and write
559E000
trusted library allocation
page read and write
129E000
heap
page read and write
CA5000
unkown
page execute and read and write
C85000
unkown
page execute and read and write
CC3000
unkown
page execute and write copy
3B0E000
stack
page read and write
424F000
stack
page read and write
1307000
heap
page read and write
1323000
heap
page read and write
D0B000
unkown
page execute and read and write
4A0E000
stack
page read and write
CA4000
unkown
page execute and write copy
D37000
unkown
page execute and write copy
12C7000
heap
page read and write
1327000
heap
page read and write
5586000
trusted library allocation
page read and write
35CF000
stack
page read and write
B20000
unkown
page execute and read and write
5280000
direct allocation
page execute and read and write
DD3000
unkown
page execute and write copy
5260000
direct allocation
page execute and read and write
34CE000
stack
page read and write
5250000
direct allocation
page execute and read and write
5100000
direct allocation
page read and write
5A0F000
stack
page read and write
4C71000
heap
page read and write
4D70000
trusted library allocation
page read and write
CC9000
unkown
page execute and read and write
414E000
stack
page read and write
124E000
stack
page read and write
D1B000
unkown
page execute and write copy
155F000
stack
page read and write
2F30000
direct allocation
page read and write
2F30000
direct allocation
page read and write
4C71000
heap
page read and write
D3B000
unkown
page execute and read and write
12F3000
heap
page read and write
398F000
stack
page read and write
135A000
heap
page read and write
5750000
remote allocation
page read and write
CF1000
unkown
page execute and read and write
528D000
stack
page read and write
DBA000
unkown
page execute and write copy
3D8E000
stack
page read and write
11D0000
heap
page read and write
55FF000
stack
page read and write
1327000
heap
page read and write
165E000
stack
page read and write
460F000
stack
page read and write
450E000
stack
page read and write
1323000
heap
page read and write
2F30000
direct allocation
page read and write
C88000
unkown
page execute and write copy
3C0F000
stack
page read and write
58AD000
stack
page read and write
12F0000
heap
page read and write
4C71000
heap
page read and write
50ED000
stack
page read and write
AC1000
unkown
page execute and write copy
590E000
stack
page read and write
5479000
trusted library allocation
page read and write
1318000
heap
page read and write
DC5000
unkown
page execute and write copy
384F000
stack
page read and write
4C71000
heap
page read and write
DAE000
unkown
page execute and write copy
2F30000
direct allocation
page read and write
4C70000
heap
page read and write
4B4E000
stack
page read and write
12D5000
heap
page read and write
B2B000
unkown
page execute and read and write
54FE000
stack
page read and write
3ACF000
stack
page read and write
5280000
direct allocation
page execute and read and write
39CE000
stack
page read and write
CAD000
unkown
page execute and write copy
4C71000
heap
page read and write
B2C000
unkown
page execute and write copy
5750000
remote allocation
page read and write
1318000
heap
page read and write
2F1E000
stack
page read and write
2F30000
direct allocation
page read and write
1327000
heap
page read and write
12DE000
heap
page read and write
CA7000
unkown
page execute and read and write
304F000
stack
page read and write
1372000
heap
page read and write
12F3000
heap
page read and write
12F0000
heap
page read and write
2F30000
direct allocation
page read and write
1323000
heap
page read and write
5280000
direct allocation
page execute and read and write
49CF000
stack
page read and write
DD4000
unkown
page execute and write copy
410F000
stack
page read and write
4C71000
heap
page read and write
2F30000
direct allocation
page read and write
116D000
stack
page read and write
523F000
stack
page read and write
5100000
direct allocation
page read and write
CAD000
unkown
page execute and read and write
CDE000
unkown
page execute and write copy
428E000
stack
page read and write
12D0000
heap
page read and write
5100000
direct allocation
page read and write
488F000
stack
page read and write
5280000
direct allocation
page execute and read and write
2F30000
direct allocation
page read and write
5290000
direct allocation
page execute and read and write
D43000
unkown
page execute and write copy
12D9000
heap
page read and write
44CF000
stack
page read and write
DBD000
unkown
page execute and read and write
2F30000
direct allocation
page read and write
4C71000
heap
page read and write
5750000
remote allocation
page read and write
DBE000
unkown
page execute and write copy
4C80000
heap
page read and write
5280000
direct allocation
page execute and read and write
4C71000
heap
page read and write
4C71000
heap
page read and write
1290000
heap
page read and write
2F30000
direct allocation
page read and write
D22000
unkown
page execute and write copy
D45000
unkown
page execute and read and write
DD3000
unkown
page execute and read and write
338E000
stack
page read and write
11C0000
heap
page read and write
438F000
stack
page read and write
1363000
heap
page read and write
400E000
stack
page read and write
314F000
stack
page read and write
D64000
unkown
page execute and write copy
4B0F000
stack
page read and write
D2B000
unkown
page execute and write copy
11F5000
heap
page read and write
4C71000
heap
page read and write
3D4F000
stack
page read and write
129A000
heap
page read and write
11F0000
heap
page read and write
573E000
stack
page read and write
DA7000
unkown
page execute and read and write
57AD000
stack
page read and write
388E000
stack
page read and write
AC0000
unkown
page readonly
3C4E000
stack
page read and write
5270000
direct allocation
page execute and read and write
474F000
stack
page read and write
D06000
unkown
page execute and write copy
2E5E000
stack
page read and write
D4C000
unkown
page execute and write copy
48CE000
stack
page read and write
12D8000
heap
page read and write
4C71000
heap
page read and write
557A000
trusted library allocation
page read and write
348F000
stack
page read and write
5591000
trusted library allocation
page read and write
4C71000
heap
page read and write
12DE000
heap
page read and write
374E000
stack
page read and write
3ECE000
stack
page read and write
464E000
stack
page read and write
370F000
stack
page read and write
478E000
stack
page read and write
1327000
heap
page read and write
2EDE000
stack
page read and write
1306000
heap
page read and write
D2F000
unkown
page execute and read and write
43CE000
stack
page read and write
AC0000
unkown
page read and write
4C71000
heap
page read and write
B2A000
unkown
page execute and write copy
128E000
stack
page read and write
52A0000
direct allocation
page execute and read and write
4C71000
heap
page read and write
360E000
stack
page read and write
3E8F000
stack
page read and write
CA6000
unkown
page execute and write copy
4C71000
heap
page read and write
2F40000
heap
page read and write
2F30000
direct allocation
page read and write
1359000
heap
page read and write
4C71000
heap
page read and write
DC5000
unkown
page execute and write copy
513E000
stack
page read and write
5280000
direct allocation
page execute and read and write
54BD000
stack
page read and write
DBA000
unkown
page execute and write copy
563E000
stack
page read and write
106C000
stack
page read and write
2F30000
direct allocation
page read and write
4C4F000
stack
page read and write
D24000
unkown
page execute and read and write
4C71000
heap
page read and write
D4E000
unkown
page execute and read and write
4C71000
heap
page read and write
4C71000
heap
page read and write
2F47000
heap
page read and write
DA4000
unkown
page execute and write copy
52B0000
direct allocation
page execute and read and write
2F30000
direct allocation
page read and write
52C5000
trusted library allocation
page read and write
1323000
heap
page read and write
2E9C000
stack
page read and write
1318000
heap
page read and write
D21000
unkown
page execute and read and write
334F000
stack
page read and write
2F20000
heap
page read and write
There are 208 hidden memdumps, click here to show them.