IOC Report
file.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\file.exe
"C:\Users\user\Desktop\file.exe"
malicious

URLs

Name
IP
Malicious
studennotediw.store
malicious
dissapoiznw.store
malicious
https://steamcommunity.com/profiles/76561199724331900
104.102.49.254
malicious
https://steamcommunity.com:443/profiles/76561199724331900
unknown
malicious
eaglepawnoy.store
malicious
bathdoomgaz.store
malicious
clearancek.site
malicious
spirittunek.store
malicious
licendfilteo.site
malicious
https://player.vimeo.com
unknown
https://steamcommunity.com/?subsection=broadcasts
unknown
https://community.cloudflare.steamstatic.com/public/shared/javascript/shared_global.js?v=wJD9maDpDcV
unknown
https://sergei-esenin.com/
unknown
https://store.steampowered.com/subscriber_agreement/
unknown
https://www.gstatic.cn/recaptcha/
unknown
https://community.cloudflare.steamstatic.com/public/javascript/modalContent.js?v=UuGFpt56D9L4&l=
unknown
https://community.cloudflare.steamstatic.com/public/javascript/modalv2.js?v=dfMhuy-Lrpyo&l=engli
unknown
https://community.cloudflare.steamstatic.com/public/javascript/promo/stickers.js?v=GfA42_x2_aub&
unknown
https://community.cloudflare.steamstatic.com/public/javascript/scriptaculous/_combined.js?v=OeNIgrpE
unknown
http://www.valvesoftware.com/legal.htm
unknown
https://www.youtube.com
unknown
https://www.google.com
unknown
https://www.valvesoftware.com/en/contact?contact-person=Translation%20Team%20Feedback
unknown
https://s.ytimg.com;
unknown
https://steam.tv/
unknown
https://clearancek.site:443/apiiH
unknown
https://community.cloudflare.steamstatic.com/public/javascript/applications/community/main.js?v=W9BX
unknown
https://community.cloudflare.steamstatic.com/public/javascript/prototype-1.7.js?v=.55t44gwuwgvw&
unknown
https://s.y
unknown
http://store.steampowered.com/privacy_agreement/
unknown
https://community.cloudflare.steamstatic.com/public/shared/css/shared_responsive.css?v=eghn9DNyCY67&
unknown
https://sergei-esenin.com/LIjb7
unknown
https://store.steampowered.com/points/shop/
unknown
https://community.cloudflare.steamstatic.com/public/css/promo/summer2017/stickers.css?v=bZKSp7oNwVPK
unknown
https://community.cloudflare.steamstatic.com/public/javascript/reportedcontent.js?v=dAtjbcZMWhSe&amp
unknown
https://community.cloudflare.steamstatic.com/public/css/skin_1/modalContent.css?v=.VpiwkLAYt9r1&
unknown
https://sketchfab.com
unknown
https://lv.queniujq.cn
unknown
https://steamcommunity.com/profiles/76561199724331900/inventory/
unknown
https://www.youtube.com/
unknown
https://store.steampowered.com/privacy_agreement/
unknown
https://cdn.cloudflare.steamstatic.com/steamcommunity/public/assets/
unknown
https://community.cloudflare.steamstatic.com/public/javascript/webui/clientcom.js?v=qYlgdgWOD4Ng&amp
unknown
https://community.cloudflare.steamstatic.com/public/shared/images/responsive/logo_valve_footer.png
unknown
https://sergei-esenin.com:443/api
unknown
https://community.cloudflare.steamstatic.com/public/shared/images/header/logo_steam.svg?t=962016
unknown
https://www.google.com/recaptcha/
unknown
https://checkout.steampowered.com/
unknown
https://login.st
unknown
https://community.cloudflare.steamstatic.com/public/javascript/applications/community/libraries~b28b
unknown
https://community.cloudflare.steamstatic.com/public/shared/images/responsive/header_logo.png
unknown
https://store.steampowered.com/;
unknown
https://community.cloudflare.steamstatic.com/public/javascript/profile.js?v=KkhJqW2NGKiM&l=engli
unknown
https://store.steampowered.com/about/
unknown
https://community.cloudflare.steamstatic.com/
unknown
https://steamcommunity.com/my/wishlist/
unknown
https://avatars.cloudflare.steamstatic.com/fef49e7fa7e1997310d705b2a6158ff8dL
unknown
https://community.cloudflare.steamstatic.com/public/javascript/jquery-1.11.1.min.js?v=.isFTSRckeNhC&
unknown
https://help.steampowered.com/en/
unknown
https://steamcommunity.com/market/
unknown
https://store.steampowered.com/news/
unknown
https://steambroadcast.akamaized.ne
unknown
http://store.steampowered.com/subscriber_agreement/
unknown
https://community.cloudflare.steamstatic.com/public/javascript/applications/community/manifest.js?v=
unknown
https://steamcommunity.com/linkfilter/?u=http%3A%2F%2Fwww.geonames.org
unknown
https://community.cloudflare.steamstatic.com/public/css/applications/community/main.css?v=ljhW-PbGuX
unknown
https://recaptcha.net/recaptcha/;
unknown
http://127.0s
unknown
https://sergei-esenin.com/apiW
unknown
https://steamcommunity.com/discussions/
unknown
https://store.steampowered.com/stats/
unknown
https://community.cloudflare.steamstatic.com/public/javascript/global.js?v=bOP7RorZq4_W&l=englis
unknown
https://medal.tv
unknown
https://broadcast.st.dl.eccdnx.com
unknown
https://community.cloudflare.steamstatic.com/public/shared/javascript/tooltip.js?v=.zYHOpI1L3Rt0&amp
unknown
https://store.steampowered.com/steam_refunds/
unknown
https://community.cloudflare.steamstatic.com/public/images/skin_1/arrowDn9x5.gif
unknown
https://community.cloudflare.steamstatic.com/public/shared/javascript/shared_responsive_adapter.js?v
unknown
https://community.cloudflare.steamstatic.com/public/shared/images/responsive/header_menu_hamburger.p
unknown
https://steamcommunity.com/login/home/?goto=profiles%2F76561199724331900
unknown
https://community.cloudflare.steamstatic.com/public/shared/javascript/auth_refresh.js?v=WgUxSlKTb3W1
unknown
https://sergei-esenin.com/apiN=pc
unknown
https://steamcommunity.com/workshop/
unknown
https://login.steampowered.com/
unknown
https://store.steampowered.com/legal/
unknown
https://community.cloudflare.steamstatic.com/public/shared/css/buttons.css?v=tuNiaSwXwcYT&l=engl
unknown
https://community.cloudflare.steamstatic.com/public/shared/css/motiva_sans.css?v=GfSjbGKcNYaQ&l=
unknown
https://community.cloudflare.steamstatic.com/public/css/skin_1/profilev2.css?v=gNE3gksLVEVa&l=en
unknown
https://community.cloudflare.steamstatic.com/public/css/globalv2.css?v=pwVcIAtHNXwg&l=english&am
unknown
https://community.cloudflare.steamstatic.com/public/css/skin_1/header.css?v=vh4BMeDcNiCU&l=engli
unknown
https://recaptcha.net
unknown
https://store.steampowered.com/
unknown
https://community.cloudflare.steamstatic.com/public/shared/css/shared_global.css?v=Ff_1prscqzeu&
unknown
https://mobbipenju.store:443/api
unknown
https://store.steampowered.com/;Persistent-AuthWWW-AuthenticateVarysteamCountry=US%7C42cb6563c5fec81
unknown
http://127.0.0.1:27060
unknown
https://sergei-esenin.com/TIbb6
unknown
https://spirittunek.store:443/apii
unknown
https://cdn.clo
unknown
https://community.cloudflare.steamstatic.com/public/images/skin_1/footerLogo_valve.png?v=1
unknown
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
steamcommunity.com
104.102.49.254
malicious
eaglepawnoy.store
unknown
malicious
bathdoomgaz.store
unknown
malicious
spirittunek.store
unknown
malicious
licendfilteo.site
unknown
malicious
studennotediw.store
unknown
malicious
mobbipenju.store
unknown
malicious
clearancek.site
unknown
malicious
dissapoiznw.store
unknown
malicious
sergei-esenin.com
unknown

IPs

IP
Domain
Country
Malicious
104.102.49.254
steamcommunity.com
United States
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
A01000
unkown
page execute and read and write
malicious
357F000
stack
page read and write
447E000
stack
page read and write
4D41000
heap
page read and write
13A0000
heap
page read and write
473E000
stack
page read and write
169F000
stack
page read and write
56AF000
stack
page read and write
3ABE000
stack
page read and write
3BFE000
stack
page read and write
4AFE000
stack
page read and write
154B000
heap
page read and write
D15000
unkown
page execute and read and write
35BE000
stack
page read and write
C78000
unkown
page execute and read and write
3D3E000
stack
page read and write
C4F000
unkown
page execute and write copy
A60000
unkown
page execute and write copy
49BE000
stack
page read and write
C67000
unkown
page execute and read and write
157A000
heap
page read and write
154B000
heap
page read and write
487E000
stack
page read and write
C09000
unkown
page execute and write copy
14E2000
heap
page read and write
C76000
unkown
page execute and write copy
FEE000
stack
page read and write
5300000
direct allocation
page execute and read and write
14AA000
heap
page read and write
C89000
unkown
page execute and read and write
5360000
direct allocation
page execute and read and write
5628000
trusted library allocation
page read and write
5528000
trusted library allocation
page read and write
1529000
heap
page read and write
C24000
unkown
page execute and read and write
BCD000
unkown
page execute and read and write
14D7000
heap
page read and write
433F000
stack
page read and write
40FE000
stack
page read and write
3000000
direct allocation
page read and write
152F000
heap
page read and write
4ABF000
stack
page read and write
4D41000
heap
page read and write
4D41000
heap
page read and write
A6C000
unkown
page execute and write copy
3A7F000
stack
page read and write
323F000
stack
page read and write
1546000
heap
page read and write
44BE000
stack
page read and write
36FE000
stack
page read and write
1536000
heap
page read and write
3000000
direct allocation
page read and write
437E000
stack
page read and write
1589000
heap
page read and write
4C3E000
stack
page read and write
41FF000
stack
page read and write
133E000
stack
page read and write
C07000
unkown
page execute and write copy
4D41000
heap
page read and write
3020000
direct allocation
page read and write
51FE000
stack
page read and write
533D000
stack
page read and write
55AE000
stack
page read and write
563E000
trusted library allocation
page read and write
313F000
stack
page read and write
4D41000
heap
page read and write
4D41000
heap
page read and write
3E3F000
stack
page read and write
12FD000
stack
page read and write
3CFF000
stack
page read and write
152F000
heap
page read and write
5800000
remote allocation
page read and write
BFB000
unkown
page execute and write copy
BE7000
unkown
page execute and read and write
1592000
heap
page read and write
4D41000
heap
page read and write
1546000
heap
page read and write
1527000
heap
page read and write
A01000
unkown
page execute and write copy
4D41000
heap
page read and write
C4C000
unkown
page execute and write copy
5180000
trusted library allocation
page read and write
153C000
heap
page read and write
4D41000
heap
page read and write
497F000
stack
page read and write
151C000
heap
page read and write
C62000
unkown
page execute and write copy
2FBE000
stack
page read and write
343F000
stack
page read and write
1536000
heap
page read and write
153C000
heap
page read and write
C87000
unkown
page execute and write copy
45BF000
stack
page read and write
1532000
heap
page read and write
3000000
direct allocation
page read and write
3BBF000
stack
page read and write
4D41000
heap
page read and write
51BD000
stack
page read and write
3E7E000
stack
page read and write
179F000
stack
page read and write
C0E000
unkown
page execute and read and write
1501000
heap
page read and write
C23000
unkown
page execute and write copy
4D41000
heap
page read and write
2F7C000
stack
page read and write
BD0000
unkown
page execute and write copy
383E000
stack
page read and write
594E000
stack
page read and write
C80000
unkown
page execute and read and write
5370000
trusted library allocation
page read and write
4D41000
heap
page read and write
A00000
unkown
page readonly
3037000
heap
page read and write
423E000
stack
page read and write
1536000
heap
page read and write
154B000
heap
page read and write
C81000
unkown
page execute and write copy
153C000
heap
page read and write
59BE000
stack
page read and write
37FF000
stack
page read and write
14AE000
heap
page read and write
C08000
unkown
page execute and read and write
154B000
heap
page read and write
1536000
heap
page read and write
C57000
unkown
page execute and read and write
36BF000
stack
page read and write
45FE000
stack
page read and write
13C5000
heap
page read and write
3020000
direct allocation
page read and write
4D50000
heap
page read and write
556D000
stack
page read and write
BF1000
unkown
page execute and write copy
397E000
stack
page read and write
5320000
direct allocation
page execute and read and write
546D000
stack
page read and write
A00000
unkown
page read and write
D15000
unkown
page execute and write copy
C75000
unkown
page execute and read and write
D16000
unkown
page execute and write copy
153C000
heap
page read and write
5330000
direct allocation
page execute and read and write
4D41000
heap
page read and write
5330000
direct allocation
page execute and read and write
BF1000
unkown
page execute and read and write
5800000
remote allocation
page read and write
D07000
unkown
page execute and write copy
C74000
unkown
page execute and write copy
CAC000
unkown
page execute and write copy
5330000
direct allocation
page execute and read and write
57EE000
stack
page read and write
1533000
heap
page read and write
14EE000
heap
page read and write
A60000
unkown
page execute and read and write
C93000
unkown
page execute and read and write
347E000
stack
page read and write
3000000
direct allocation
page read and write
40BF000
stack
page read and write
3FBE000
stack
page read and write
5310000
direct allocation
page execute and read and write
13C0000
heap
page read and write
154B000
heap
page read and write
CFF000
unkown
page execute and write copy
D00000
unkown
page execute and write copy
5636000
trusted library allocation
page read and write
152F000
heap
page read and write
1536000
heap
page read and write
3000000
direct allocation
page read and write
4BFF000
stack
page read and write
C7F000
unkown
page execute and write copy
1527000
heap
page read and write
393F000
stack
page read and write
1532000
heap
page read and write
CFF000
unkown
page execute and read and write
3030000
heap
page read and write
5330000
direct allocation
page execute and read and write
5340000
direct allocation
page execute and read and write
3000000
direct allocation
page read and write
5ABF000
stack
page read and write
51C0000
direct allocation
page read and write
4D3F000
stack
page read and write
F70000
heap
page read and write
1390000
heap
page read and write
138E000
stack
page read and write
1529000
heap
page read and write
5350000
direct allocation
page execute and read and write
3000000
direct allocation
page read and write
52FF000
stack
page read and write
3000000
direct allocation
page read and write
CB1000
unkown
page execute and read and write
D07000
unkown
page execute and write copy
1529000
heap
page read and write
C91000
unkown
page execute and write copy
1504000
heap
page read and write
333F000
stack
page read and write
5330000
direct allocation
page execute and read and write
4D41000
heap
page read and write
F80000
heap
page read and write
3F7F000
stack
page read and write
46FF000
stack
page read and write
564B000
trusted library allocation
page read and write
5330000
direct allocation
page execute and read and write
584D000
stack
page read and write
F1C000
stack
page read and write
C86000
unkown
page execute and read and write
C2B000
unkown
page execute and write copy
4D41000
heap
page read and write
3000000
direct allocation
page read and write
3000000
direct allocation
page read and write
3000000
direct allocation
page read and write
C4E000
unkown
page execute and read and write
C35000
unkown
page execute and read and write
1526000
heap
page read and write
14A0000
heap
page read and write
BFC000
unkown
page execute and read and write
CF1000
unkown
page execute and write copy
5800000
remote allocation
page read and write
4D41000
heap
page read and write
56EE000
stack
page read and write
4D40000
heap
page read and write
4D41000
heap
page read and write
4D41000
heap
page read and write
2FFE000
stack
page read and write
153C000
heap
page read and write
3000000
direct allocation
page read and write
14DF000
heap
page read and write
483F000
stack
page read and write
4D41000
heap
page read and write
3000000
direct allocation
page read and write
CCB000
unkown
page execute and read and write
3000000
direct allocation
page read and write
There are 220 hidden memdumps, click here to show them.