IOC Report
mgEXk8ip26.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\mgEXk8ip26.exe
"C:\Users\user\Desktop\mgEXk8ip26.exe"
malicious

URLs

Name
IP
Malicious
https://community.fastly.steamstatic.com/public/shared/images/responsive/header_menu_hamburger.png
unknown
https://player.vimeo.com
unknown
https://store.steampowered.c
unknown
https://energyaffai.lat:443/apiT
unknown
https://community.fastly.steamstatic.com/public/css/promo/summer2017/stickers.css?v=Ncr6N09yZIap&amp
unknown
https://steamcommunity.com/?subsection=broadcasts
unknown
https://community.fastly.steamst
unknown
https://store.steampowered.com/subscriber_agreement/
unknown
https://www.gstatic.cn/recaptcha/
unknown
aspecteirs.lat
https://community.fastly.steamstatic.com/public/javascript/applications/community/manifest.js?v=hyEE
unknown
http://www.valvesoftware.com/legal.htm
unknown
https://community.fastly.steamstatic.com/public/shared/css/shared_global.css?v=wuA4X_n5-mo0&l=en
unknown
https://www.google.com
unknown
https://grannyejh.lat:443/api
unknown
sweepyribs.lat
https://lev-tolstoi.com/api%
unknown
https://www.valvesoftware.com/en/contact?contact-person=Translation%20Team%20Feedback
unknown
https://community.fastly.steamstatic.com/public/javascript/applications/community/libraries~b28b7af6
unknown
https://cdn.fastly.steamstatic.com/steamcommunity/public/assets/
unknown
sustainskelet.lat
rapeflowwj.lat
https://community.fastly.steamstatic.com/public/shared/css/motiva_sans.css?v=-yZgCk0Nu7kH&l=engl
unknown
https://community.fastly.steamstatic.com/public/css/skin_1/profilev2.css?v=fe66ET2uI50l&l=englis
unknown
https://community.fastly.steamstatic.com/public/javascript/scriptaculous/_combined.js?v=pbdAKOcDIgbC
unknown
https://community.fastly.steamstatic.com/public/images/skin_1/footerLogo_valve.png?v=1
unknown
https://community.fastly.steamstatic.com/public/javascript/webui/clientc
unknown
https://community.fastly.steamstatic.com/public/shared/css/buttons.css?v=qhQgyjWi6LgJ&l=english&
unknown
https://community.fastly.steamstatic.com/
unknown
https://steam.tv/
unknown
https://community.fastly.steamstatic.com/public/shared/javascript/auth_refresh.js?
unknown
https://steamcommunity.com/profiles/76561199724331900
104.102.49.254
https://community.fastly.steamstatic.com/public/javascript/promo/stickers.js?v=CcLRHsa04otQ&l=en
unknown
https://lev-tolstoi.com/
unknown
http://store.steampowered.com/privacy_agreement/
unknown
https://steamcommunity.com:443/profiles/76561199724331900
unknown
https://community.fastly.steamstatic.com/public/shared/images/responsive/logo_valve
unknown
https://store.steampowered.com/points/shop/
unknown
energyaffai.lat
https://community.fastly.steamstatic.com/public/javascript/modalv2.js?v=zBXEuexVQ0FZ&l=english&a
unknown
https://sketchfab.com
unknown
https://lv.queniujq.cn
unknown
https://aspecteirs.lat:443/api
unknown
https://steamcommunity.com/profiles/76561199724331900/inventory/
unknown
https://www.youtube.com/
unknown
https://store.steampowered.com/privacy_agreement/
unknown
https://community.fastly.steamstatic.com/public/css/skin_1/modalContent.css?v=WXAusLHclDIt&l=eng
unknown
https://community.fastly.steamstatic.
unknown
https://lev-tolstoi.com/api
104.21.66.86
https://community.fastly.steamstatic.com/public/css/promo/summer2017/sticker
unknown
https://community.fastly.steamstatic.com/public/javascript/global.js?v=jWc2JLWHx5Kn&l=english&am
unknown
https://www.google.com/recaptcha/
unknown
https://checkout.steampowered.com/
unknown
https://sweepyribs.lat:443/api
unknown
grannyejh.lat
https://store.steampowered.com/;
unknown
https://store.steampowered.com/about/
unknown
https://steamcommunity.com/my/wishlist/
unknown
https://community.fastly.steamstatic.com/pg
unknown
https://community.fastly.steamstatic.com/public/shared/css/shared_responsive.css?v=JL1e4uQSrVGe&
unknown
necklacebudi.lat
https://help.steampowered.com/en/
unknown
https://steamcommunity.com/market/
unknown
https://store.steampowered.com/news/
unknown
https://recaptcha.net/recaptcha/L
unknown
https://community.fastly.steamstatic.com/public/javascript/webui/clientcom.js?v=St3gSJx2HFUZ&l=e
unknown
http://store.steampowered.com/subscriber_agreement/
unknown
https://steamcommunity.com/linkfilter/?u=http%3A%2F%2Fwww.geonames.org
unknown
https://steamcommunity.co
unknown
https://steamcommunity.com/discussions/
unknown
https://community.f
unknown
https://store.steampowered.com/stats/
unknown
https://community.fastly.steamstatic.com/public/shared/javascript/shared_global.js?v=Gr6TbGRvDtNE&am
unknown
https://lev-tolstoi.com:443/api-
unknown
https://medal.tv
unknown
https://broadcast.st.dl.eccdnx.com
unknown
https://community.fastly.steamstatic.com/public/shared/images/responsive/logo_valve_footer.png
unknown
https://community.fastly.steamstatic.com/public/css/skin_1/header.css?v=EM4kCu67DNda&l=english&a
unknown
https://store.steampowered.com/steam_refunds/
unknown
https://avatars.fastly.steamstatic.co8
unknown
https://community.fastly.steamstatic.com/public/css/applications/community/main.css?v=Lj6X7NKUMfzk&a
unknown
https://steamcommunity.com/login/home/?goto=profiles%2F76561199724331900
unknown
https://community.fastly.steamstatic.com/public/shared/images/header/logo_steam.svg?t=962016
unknown
crosshuaht.lat
https://community.fastly.steamstatic.com/public/javascript/reportedcontent.js?v=-lZqrarogJr8&l=e
unknown
https://community.fastly.st
unknown
https://s.ytim
unknown
https://steamcommunity.com/workshop/
unknown
https://login.steampowered.com/
unknown
https://store.steam
unknown
https://community.fastly.steamstatic.com/public/css/globalv2.css?v=hzEgqbtRcI5V&l=english&_c
unknown
https://store.steampowered.com/legal/
unknown
https://community.fastly.steamstatic.com/public/shared/javascript/tooltip.js?v=QYkT4eS5mbTN&l=en
unknown
https://community.fastly.steamstatic.com/public/javascript/prototype-1.7.js?v=npJElBnrEO6W&l=eng
unknown
https://community.fastly.steamstatic.com/public/javascript/profile.js?v=GeQ6v03mWpAc&l=english&a
unknown
https://community.fastly.steamstatic.com/public/javascript/modalContent.js?v=uqf5ttWTRe7l&l=engl
unknown
https://community.fastly.steamsta
unknown
https://store.steampowered.com/
unknown
https://community.fastly.steamstatic.com/public/shared/images/responsive/header_logo.png
unknown
http://127.0.0.1:27060
unknown
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
steamcommunity.com
104.102.49.254
lev-tolstoi.com
104.21.66.86
s-part-0035.t-0009.t-msedge.net
13.107.246.63
fp2e7a.wpc.phicdn.net
192.229.221.95
sustainskelet.lat
unknown
crosshuaht.lat
unknown
rapeflowwj.lat
unknown
grannyejh.lat
unknown
aspecteirs.lat
unknown
sweepyribs.lat
unknown
discokeyus.lat
unknown
energyaffai.lat
unknown
necklacebudi.lat
unknown
There are 3 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
104.21.66.86
lev-tolstoi.com
United States
104.102.49.254
steamcommunity.com
United States

Memdumps

Base Address
Regiontype
Protect
Malicious
9C1000
unkown
page execute and read and write
malicious
5470000
trusted library allocation
page read and write
191D000
stack
page read and write
1421000
heap
page read and write
57ED000
stack
page read and write
4B5F000
stack
page read and write
13F7000
heap
page read and write
C96000
unkown
page execute and read and write
1402000
heap
page read and write
3A1E000
stack
page read and write
4E21000
heap
page read and write
4E21000
heap
page read and write
3C5F000
stack
page read and write
141C000
heap
page read and write
13E9000
heap
page read and write
556D000
stack
page read and write
5910000
remote allocation
page read and write
4E21000
heap
page read and write
3D9F000
stack
page read and write
1421000
heap
page read and write
4E21000
heap
page read and write
300E000
stack
page read and write
419E000
stack
page read and write
4E21000
heap
page read and write
5410000
direct allocation
page execute and read and write
5BCF000
stack
page read and write
13D3000
heap
page read and write
58EE000
stack
page read and write
13CE000
heap
page read and write
13CF000
heap
page read and write
339F000
stack
page read and write
13E9000
heap
page read and write
4E10000
direct allocation
page read and write
365E000
stack
page read and write
4E10000
direct allocation
page read and write
4E10000
direct allocation
page read and write
5430000
direct allocation
page execute and read and write
133D000
stack
page read and write
C71000
unkown
page execute and read and write
1405000
heap
page read and write
4CDE000
stack
page read and write
1410000
heap
page read and write
5430000
direct allocation
page execute and read and write
1402000
heap
page read and write
1456000
heap
page read and write
B92000
unkown
page execute and read and write
4E21000
heap
page read and write
5910000
remote allocation
page read and write
E41000
unkown
page execute and read and write
4E10000
direct allocation
page read and write
13EC000
heap
page read and write
4E10000
direct allocation
page read and write
4C9F000
stack
page read and write
5440000
direct allocation
page execute and read and write
1455000
heap
page read and write
1375000
heap
page read and write
13E0000
heap
page read and write
3DDE000
stack
page read and write
A12000
unkown
page write copy
1458000
heap
page read and write
13F7000
heap
page read and write
16CF000
stack
page read and write
145E000
heap
page read and write
1380000
heap
page read and write
5430000
direct allocation
page execute and read and write
4E21000
heap
page read and write
351E000
stack
page read and write
5DB0000
heap
page read and write
4E21000
heap
page read and write
3B5E000
stack
page read and write
5430000
direct allocation
page execute and read and write
1421000
heap
page read and write
4E21000
heap
page read and write
13E0000
heap
page read and write
1410000
heap
page read and write
13F7000
heap
page read and write
CAF000
unkown
page execute and write copy
13EB000
heap
page read and write
4E21000
heap
page read and write
5420000
direct allocation
page execute and read and write
1405000
heap
page read and write
13C8000
heap
page read and write
13E9000
heap
page read and write
5260000
trusted library allocation
page read and write
A12000
unkown
page write copy
3EDF000
stack
page read and write
5430000
direct allocation
page execute and read and write
4E20000
heap
page read and write
4E21000
heap
page read and write
38DE000
stack
page read and write
4B9E000
stack
page read and write
42DE000
stack
page read and write
1402000
heap
page read and write
1410000
heap
page read and write
1410000
heap
page read and write
1370000
heap
page read and write
5460000
direct allocation
page execute and read and write
4E21000
heap
page read and write
13D3000
heap
page read and write
3C9E000
stack
page read and write
13C5000
heap
page read and write
415F000
stack
page read and write
1402000
heap
page read and write
4DF0000
heap
page read and write
479F000
stack
page read and write
CA0000
unkown
page execute and read and write
441D000
stack
page read and write
4E10000
direct allocation
page read and write
1453000
heap
page read and write
4E10000
direct allocation
page read and write
455E000
stack
page read and write
4E21000
heap
page read and write
13CF000
heap
page read and write
4E21000
heap
page read and write
4A1F000
stack
page read and write
A03000
unkown
page execute and read and write
595D000
stack
page read and write
141C000
heap
page read and write
5400000
direct allocation
page execute and read and write
1402000
heap
page read and write
1458000
heap
page read and write
52B0000
direct allocation
page read and write
CAE000
unkown
page execute and write copy
1405000
heap
page read and write
13F7000
heap
page read and write
4E10000
direct allocation
page read and write
5910000
remote allocation
page read and write
4E21000
heap
page read and write
9C0000
unkown
page read and write
315C000
stack
page read and write
329E000
stack
page read and write
52F2000
direct allocation
page read and write
401F000
stack
page read and write
1458000
heap
page read and write
141C000
heap
page read and write
13EB000
heap
page read and write
CAE000
unkown
page execute and read and write
13B7000
heap
page read and write
4E10000
direct allocation
page read and write
1480000
heap
page read and write
361F000
stack
page read and write
13D3000
heap
page read and write
4E10000
direct allocation
page read and write
325F000
stack
page read and write
5430000
direct allocation
page execute and read and write
1560000
heap
page read and write
47DE000
stack
page read and write
465F000
stack
page read and write
4E21000
heap
page read and write
9C1000
unkown
page execute and write copy
43DF000
stack
page read and write
13B7000
heap
page read and write
123B000
stack
page read and write
1420000
heap
page read and write
4A5E000
stack
page read and write
13E9000
heap
page read and write
48DF000
stack
page read and write
3B1F000
stack
page read and write
4E21000
heap
page read and write
39DF000
stack
page read and write
3117000
heap
page read and write
4E21000
heap
page read and write
405E000
stack
page read and write
1405000
heap
page read and write
52B0000
direct allocation
page read and write
13E0000
heap
page read and write
138A000
heap
page read and write
138E000
heap
page read and write
3110000
heap
page read and write
4E10000
direct allocation
page read and write
4E10000
direct allocation
page read and write
5450000
direct allocation
page execute and read and write
13F7000
heap
page read and write
1405000
heap
page read and write
13B3000
heap
page read and write
53EF000
stack
page read and write
1405000
heap
page read and write
5ACE000
stack
page read and write
1A1E000
stack
page read and write
469E000
stack
page read and write
4DDF000
stack
page read and write
4DE0000
heap
page read and write
543E000
stack
page read and write
375F000
stack
page read and write
1453000
heap
page read and write
4E21000
heap
page read and write
4E31000
heap
page read and write
429F000
stack
page read and write
34DF000
stack
page read and write
57AF000
stack
page read and write
4E10000
direct allocation
page read and write
4E21000
heap
page read and write
310F000
stack
page read and write
13F7000
heap
page read and write
566E000
stack
page read and write
33DE000
stack
page read and write
1421000
heap
page read and write
4E21000
heap
page read and write
141C000
heap
page read and write
1410000
heap
page read and write
13D3000
heap
page read and write
13C8000
heap
page read and write
1468000
heap
page read and write
13C5000
heap
page read and write
1410000
heap
page read and write
3F1E000
stack
page read and write
15CE000
stack
page read and write
E42000
unkown
page execute and write copy
389F000
stack
page read and write
52B0000
direct allocation
page read and write
52EC000
stack
page read and write
56AE000
stack
page read and write
A14000
unkown
page execute and read and write
4E21000
heap
page read and write
451F000
stack
page read and write
52AD000
stack
page read and write
9C0000
unkown
page readonly
141B000
heap
page read and write
5A5D000
stack
page read and write
491E000
stack
page read and write
13CF000
heap
page read and write
4E10000
direct allocation
page read and write
379E000
stack
page read and write
1402000
heap
page read and write
There are 214 hidden memdumps, click here to show them.