IOC Report
3ZD5tEC5DH.exe

loading gif

Files

File Path
Type
Category
Malicious
3ZD5tEC5DH.exe
PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\3ZD5tEC5DH.exe.log
CSV text
modified
malicious
\Device\ConDrv
ASCII text, with CRLF, LF line terminators
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\3ZD5tEC5DH.exe
"C:\Users\user\Desktop\3ZD5tEC5DH.exe"
malicious
C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe
"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe"
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1

URLs

Name
IP
Malicious
https://drawzhotdog.shop/api
172.67.162.108
malicious
lootebarrkeyn.shop
malicious
https://gutterydhowi.shop/api
104.21.4.136
malicious
stogeneratmns.shop
malicious
reinforcenh.shop
malicious
https://reinforcenh.shop/api
172.67.208.139
malicious
ghostreedmnu.shop
malicious
https://steamcommunity.com/profiles/76561199724331900
104.102.49.254
malicious
https://vozmeatillu.shop/api
188.114.96.3
malicious
https://stogeneratmns.shop/api
188.114.96.3
malicious
https://steamcommunity.com/profiles/76561199724331900/inventory/
unknown
malicious
https://ghostreedmnu.shop/api
188.114.97.3
malicious
fragnantbui.shop
malicious
gutterydhowi.shop
malicious
https://offensivedzvju.shop/api
188.114.96.3
malicious
https://fragnantbui.shop/api
188.114.96.3
malicious
offensivedzvju.shop
malicious
drawzhotdog.shop
malicious
https://performenj.shop/api
172.67.189.2
malicious
vozmeatillu.shop
malicious
https://steamcommunity.com/profiles/76561199724331900/badges
unknown
malicious
https://community.akamai.steamstatic.com/public/javascript/global.js?v=9OzcxMXbaV84&l=english
unknown
https://community.akamai.steamstatic.com/public/javascript/jquery-1.11.1.min.js?v=.isFTS
unknown
https://community.akamai.steamstatic.com/public/shared/css/motiva_sans.css?v=gC
unknown
https://avatars.akamai.steamstatic.com/fef49e7fa7e1997310d705b2a6158ff
unknown
https://community.akamai.steamstatic.com/public/javascript/promo/stickers.js?v=upl9NJ5D2xkP&l
unknown
https://community.akamai.steamstatic.com/public/javascript/webui/clientcom.js?v=B0lGn8MokmdT&l=e
unknown
http://store.steampowered.com/subscriber_agreement/
unknown
https://steamcommunity.com/linkfilter/?u=http%3A%2F%2Fwww.geonames.org
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/libraries~b28b7af6
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/modalContent.css?v=.VpiwkLAYt9r1
unknown
https://offensivedzvju.shop/
unknown
https://performenj.shop/6&
unknown
https://vozmeatillu.shop/
unknown
https://stogeneratmns.shop/&-7
unknown
https://community.akamai.steamstatic.com/public/css/promo/summer2017/stickers.css?v=HA2Yr5oy3FFG&amp
unknown
https://steamcommunity.com/N
unknown
https://community.akamai.steamstatic.com/public/css/promo/summer2017/stickers.c
unknown
https://community.akamai.steamstatic.com/public/images/skin_1/footerLogo_valve.png?v=1
unknown
https://reinforcenh.shop/d&
unknown
https://community.akamai.steamstatic.com/public/shared/css/shared_responsive.css?v=sHIIcMzCffX6&
unknown
https://offensivedzvju.shop/W
unknown
https://avatars.akamai.steamstatic.com/fef49e7fa7e199731
unknown
https://community.akamai.steamstatic.com/public/javascript/scriptaculous/_combined.js?v=OeNIgrpEF8tL
unknown
https://store.steampowered.com/legal/
unknown
https://community.akamai.steamstatic.com/public/javascript/reportedcontent.js?v=dAtjbcZMWhSe&l=e
unknown
https://drawzhotdog.shop/
unknown
https://ghostreedmnu.shop/
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/header.css?v=NFoCa4OkAxRb&l=english
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/shared_responsive_adapter.js?v=pSv
unknown
https://performenj.shop/pi
unknown
https://community.akamai.steamstatic.com/public/shared/css/motiva_sans.css?v=-DH0xTYpnVe2&l=engl
unknown
https://performenj.shop/
unknown
https://gutterydhowi.shop/apiO
unknown
http://store.steampowered.com/privacy_agreement/
unknown
https://community.akamaoE
unknown
https://community.akamai.steamstatic.com/public/javascript/prototype-1.7.js?v=.55t44gwuwgvw
unknown
https://community.akamai.steamstatic.com/public/images/skin_1/arrowDn9x5.gif
unknown
https://avatars.akamai.steamstatic.com/fef49e7fa7e1997310d705b2a6158ff8dc1cdfeb_full.jpg
unknown
https://community.akamai.steamstatic.com/public/shared/css/shared_global.css?v=ezWS9te9Zwm9&l=en
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/tooltip.js?v=.zYHOpI1L3Rt0
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/main.js?v=PzKBszTg
unknown
https://performenj.shop/apit
unknown
https://stogeneratmns.shop/apiJ
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/shared_global.js?v=REEGJU1hwkYl&am
unknown
https://community.akamai.steamstatic.com/public/shared/css/buttons.css?v=PUJIfhtcQn7W&l=english
unknown
https://community.akamai.steamstatic.com/public/css/globalv2.css?v=PAcV2zMBzzSV&l=english
unknown
https://community.akamai.steamstatic.com/public/javascript/modalv2.js?v=dfMhuy-Lrpyo&l=english
unknown
http://store.steampowered.com/account/cookiepreferences/
unknown
https://steamcommunity.com/
unknown
https://community.akamai.steamstatic.com/public/javascript/profile.js?v=f3vWO7swdDqp&l=english
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/profilev2.css?v=M_qL4gO2sKII&l=englis
unknown
https://community.akamai.steamstatic.com/public/javascript/jquery-1.11.1.min.js?v=.isFTSRckeNhC
unknown
There are 63 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
fragnantbui.shop
188.114.96.3
malicious
performenj.shop
172.67.189.2
malicious
gutterydhowi.shop
104.21.4.136
malicious
offensivedzvju.shop
188.114.96.3
malicious
stogeneratmns.shop
188.114.96.3
malicious
reinforcenh.shop
172.67.208.139
malicious
drawzhotdog.shop
172.67.162.108
malicious
ghostreedmnu.shop
188.114.97.3
malicious
vozmeatillu.shop
188.114.96.3
malicious
lootebarrkeyn.shop
unknown
malicious
steamcommunity.com
104.102.49.254
fp2e7a.wpc.phicdn.net
192.229.221.95
There are 2 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
104.21.4.136
gutterydhowi.shop
United States
malicious
172.67.189.2
performenj.shop
United States
malicious
188.114.97.3
ghostreedmnu.shop
European Union
malicious
172.67.162.108
drawzhotdog.shop
United States
malicious
188.114.96.3
fragnantbui.shop
European Union
malicious
172.67.208.139
reinforcenh.shop
United States
malicious
104.102.49.254
steamcommunity.com
United States

Memdumps

Base Address
Regiontype
Protect
Malicious
D60000
heap
page read and write
36A5000
trusted library allocation
page read and write
7AE000
stack
page read and write
C20000
trusted library allocation
page read and write
EBA000
heap
page read and write
11BE000
stack
page read and write
F1F000
heap
page read and write
F9A000
heap
page read and write
B5B000
trusted library allocation
page execute and read and write
F6F000
heap
page read and write
2690000
heap
page execute and read and write
977000
heap
page read and write
9B9000
heap
page read and write
2AAD000
stack
page read and write
DDE000
stack
page read and write
E10000
heap
page read and write
460000
remote allocation
page execute and read and write
95E000
heap
page read and write
94A000
trusted library allocation
page execute and read and write
B4F000
stack
page read and write
950000
heap
page read and write
924000
trusted library allocation
page read and write
3278000
trusted library allocation
page read and write
985000
heap
page read and write
923000
trusted library allocation
page execute and read and write
2CAF000
stack
page read and write
F76000
heap
page read and write
640000
heap
page read and write
E5D000
stack
page read and write
24A0000
heap
page read and write
F14000
heap
page read and write
EFF000
heap
page read and write
993000
heap
page read and write
1200000
heap
page read and write
720000
heap
page read and write
7B5000
heap
page read and write
F91000
heap
page read and write
1E0000
unkown
page readonly
23E000
unkown
page readonly
302E000
stack
page read and write
2BAE000
stack
page read and write
C30000
heap
page read and write
326F000
stack
page read and write
26A3000
trusted library allocation
page read and write
DE0000
heap
page read and write
E9E000
stack
page read and write
26A1000
trusted library allocation
page execute and read and write
95A000
heap
page read and write
EB0000
heap
page read and write
F25000
heap
page read and write
316E000
stack
page read and write
36A1000
trusted library allocation
page read and write
936000
trusted library allocation
page read and write
BFE000
stack
page read and write
ED7000
heap
page read and write
B57000
trusted library allocation
page execute and read and write
F8D000
heap
page read and write
934000
trusted library allocation
page read and write
BBE000
stack
page read and write
76E000
stack
page read and write
400000
remote allocation
page execute and read and write
117F000
stack
page read and write
F0B000
heap
page read and write
8BF000
stack
page read and write
F78000
heap
page read and write
2DC000
stack
page read and write
EE9000
heap
page read and write
1E2000
unkown
page readonly
CFC000
stack
page read and write
930000
trusted library allocation
page read and write
F02000
heap
page read and write
97C000
heap
page read and write
C00000
trusted library allocation
page execute and read and write
7B0000
heap
page read and write
3287000
trusted library allocation
page read and write
312D000
stack
page read and write
3D8000
stack
page read and write
C10000
heap
page read and write
EE3000
heap
page read and write
25AF000
stack
page read and write
9FC000
stack
page read and write
D70000
heap
page read and write
910000
trusted library allocation
page read and write
E15000
heap
page read and write
479D000
stack
page read and write
3270000
trusted library allocation
page read and write
F72000
heap
page read and write
8D0000
heap
page read and write
There are 78 hidden memdumps, click here to show them.