IOC Report
file.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\file.exe
"C:\Users\user\Desktop\file.exe"
malicious

URLs

Name
IP
Malicious
studennotediw.stor
malicious
spirittunek.stor
malicious
eaglepawnoy.stor
malicious
clearancek.site
malicious
mobbipenju.stor
malicious
https://steamcommunity.com/profiles/76561199724331900
104.102.49.254
malicious
licendfilteo.site
malicious
https://steamcommunity.com/profiles/76561199724331900/inventory/
unknown
malicious
bathdoomgaz.stor
malicious
https://sensatinwu.buzz/api
188.114.96.3
malicious
dissapoiznw.stor
malicious
https://steamcommunity.com/profiles/76561199724331900/badges
unknown
malicious
https://steamcommunity.com/my/wishlist/
unknown
https://community.akamai.steamstatic.com/public/javascript/global.js?v=9OzcxMXbaV84&l=english
unknown
https://sensatinwu.buzz/apiq
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/auth_refresh.js?v=WgUxSlKTb3W1&amp
unknown
https://steamcommunity.com/?subsection=broadcasts
unknown
https://help.steampowered.com/en/
unknown
https://steamcommunity.com/market/
unknown
https://store.steampowered.com/news/
unknown
https://community.akamai.steamstatic.com/public/javascript/applicat4
unknown
https://store.steampowered.com/subscriber_agreement/
unknown
http://store.steampowered.com/subscriber_agreement/
unknown
https://steamcommunity.com/linkfilter/?u=http%3A%2F%2Fwww.geonames.org
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/libraries~b28b7af6
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/modalContent.css?v=.VpiwkLAYt9r1
unknown
https://community.akamai.steamstatic.com/public/javascript/promo/stickers.js?v=upl9NJ5D2xkP&l=en
unknown
http://www.valvesoftware.com/legal.htm
unknown
https://steamcommunity.com/discussions/
unknown
https://community.akamai.steamstatic.com/public/css/promo/summer2017/stickers.css?v=HA2Yr5oy3FFG&amp
unknown
https://community.akamai.steamstatic.com/public/javascript/webui/clientcom.js?v=9yzMGndrVfY4&l=e
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/logo_valve_footer.png
unknown
https://store.steampowered.com/stats/
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/header_menu_hamburger.png
unknown
https://community.akamai.steamstatic.com/public/images/skin_1/footerLogo_valve.png?v=1
unknown
https://store.steampowered.com/steam_refunds/
unknown
https://community.akamai.steamstatic.com/public/shared/css/shared_responsive.css?v=sHIIcMzCffX6&
unknown
https://www.valvesoftware.com/en/contact?contact-person=Translation%20Team%20Feedback
unknown
https://steamcommunity.com/login/home/?goto=profiles%2F76561199724331900
unknown
https://community.akamai.steamstatic.com/public/javascript/scriptaculous/_combined.js?v=OeNIgrpEF8tL
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/manifest.js?v=AeTz
unknown
https://sensatinwu.buzz/
unknown
https://steamcommunity.com/workshop/
unknown
https://store.steampowered.com/legal/
unknown
https://community.akamai.steamstatic.com/public/javascript/reportedcontent.js?v=dAtjbcZMWhSe&l=e
unknown
https://community.akamai.steamstat
unknown
https://avatars.akamai.steamstatt
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/header.css?v=NFoCa4OkAxRb&l=english
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/shared_responsive_adapter.js?v=pSv
unknown
https://community.akamai.steamstatic.com/public/shared/css/motiva_sans.css?v=-DH0xTYpnVe2&l=engl
unknown
https://steamcommunity.com/p
unknown
http://store.steampowered.com/privacy_agreement/
unknown
https://store.steampowered.com/points/shop/
unknown
https://store.steampowered.com/
unknown
https://community.akamai.steamstatic.com/public/javascript/prototype-1.7.js?v=.55t44gwuwgvw
unknown
https://community.akamai.steamstatic.com/public/images/skin_1/arrowDn9x5.gif
unknown
https://community.akamai.steamstatic.com/public/css/applications/community/main.css?v=Ev2sBLgkgyWJ&a
unknown
https://avatars.akamai.steamstatic.com/fef49e7fa7e1997310d705b2a6158ff8dc1cdfeb_full.jpg
unknown
https://store.steampowered.com/privacy_agreement/
unknown
https://community.akamai.steamstatic.com/public/shared/css/shared_global.css?v=ezWS9te9Zwm9&l=en
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/tooltip.js?v=.zYHOpI1L3Rt0
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/main.js?v=10oP_O2R
unknown
https://community.akamai.steamstatic.com/public/shared/images/header/logo_steam.svg?t=962016
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/shared_global.js?v=REEGJU1hwkYl&am
unknown
https://community.akamai.steamstatic.com/public/shared/css/buttons.css?v=PUJIfhtcQn7W&l=english
unknown
https://community.akamai.steamstatic.com/public/css/globalv2.css?v=PAcV2zMBzzSV&l=english
unknown
https://community.akamai.steamstatic.com/public/javascript/modalv2.js?v=dfMhuy-Lrpyo&l=english
unknown
http://store.steampowered.com/account/cookiepreferences/
unknown
https://store.steampowered.com/mobile
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/header_logo.png
unknown
https://steamcommunity.com/
unknown
https://community.akamai.steamstatic.com/public/javascript/profile.js?v=f3vWO7swdDqp&l=english
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/profilev2.css?v=M_qL4gO2sKII&l=englis
unknown
https://community.akamai.steamstatic.com/public/javascriH
unknown
https://community.akamai.steamstatic.com/public/javascript/jquery-1.11.1.min.js?v=.isFTSRckeNhC
unknown
https://community.akamai.steamstatic.com/public/javascript/modalContent.js?v=f2hMA1v9Zkc8&l=engl
unknown
https://store.steampowered.com/about/
unknown
There are 67 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
sensatinwu.buzz
188.114.96.3
malicious
licendfilteo.site
unknown
malicious
clearancek.site
unknown
malicious
steamcommunity.com
104.102.49.254
eaglepawnoy.store
unknown
bathdoomgaz.store
unknown
spirittunek.store
unknown
studennotediw.store
unknown
mobbipenju.store
unknown
dissapoiznw.store
unknown

IPs

IP
Domain
Country
Malicious
188.114.96.3
sensatinwu.buzz
European Union
malicious
104.102.49.254
steamcommunity.com
United States

Memdumps

Base Address
Regiontype
Protect
Malicious
5B1000
unkown
page execute and read and write
malicious
F0A000
heap
page read and write
47DF000
stack
page read and write
ED4000
heap
page read and write
4C9E000
stack
page read and write
BEE000
stack
page read and write
2BDF000
stack
page read and write
5B0000
unkown
page read and write
351F000
stack
page read and write
4F0E000
stack
page read and write
47E0000
heap
page read and write
FC2000
heap
page read and write
ED4000
heap
page read and write
2AA0000
direct allocation
page read and write
4C50000
remote allocation
page read and write
29DE000
stack
page read and write
2AA0000
direct allocation
page read and write
53C000
stack
page read and write
4C20000
heap
page read and write
F8D000
heap
page read and write
51CE000
stack
page read and write
FC1000
heap
page read and write
2AA0000
direct allocation
page read and write
32DE000
stack
page read and write
ED4000
heap
page read and write
47F0000
heap
page read and write
ED4000
heap
page read and write
4DD0000
direct allocation
page execute and read and write
2AC0000
direct allocation
page read and write
47E1000
heap
page read and write
4C50000
remote allocation
page read and write
405F000
stack
page read and write
FD2000
heap
page read and write
ED4000
heap
page read and write
FC0000
heap
page read and write
785000
unkown
page execute and read and write
F60000
heap
page read and write
2AA0000
direct allocation
page read and write
2AD7000
heap
page read and write
391E000
stack
page read and write
F7A000
heap
page read and write
2F1E000
stack
page read and write
47E1000
heap
page read and write
3F5E000
stack
page read and write
42DF000
stack
page read and write
2AA0000
direct allocation
page read and write
ED4000
heap
page read and write
3B9E000
stack
page read and write
547E000
stack
page read and write
2AA0000
direct allocation
page read and write
F60000
heap
page read and write
530D000
stack
page read and write
445E000
stack
page read and write
F4F000
heap
page read and write
2A9E000
stack
page read and write
504D000
stack
page read and write
ED4000
heap
page read and write
F49000
heap
page read and write
2A5E000
stack
page read and write
8AD000
unkown
page execute and read and write
508E000
stack
page read and write
ED4000
heap
page read and write
ED4000
heap
page read and write
2A1C000
stack
page read and write
ED4000
heap
page read and write
441F000
stack
page read and write
459E000
stack
page read and write
2DDF000
stack
page read and write
4E16000
trusted library allocation
page read and write
EF0000
heap
page read and write
46DE000
stack
page read and write
4C20000
trusted library allocation
page read and write
F39000
heap
page read and write
315F000
stack
page read and write
4DF0000
direct allocation
page execute and read and write
4DE0000
direct allocation
page execute and read and write
355E000
stack
page read and write
301F000
stack
page read and write
894000
unkown
page execute and read and write
4DDD000
stack
page read and write
F4B000
heap
page read and write
ED4000
heap
page read and write
11FF000
stack
page read and write
47E1000
heap
page read and write
B4D000
stack
page read and write
ED4000
heap
page read and write
419F000
stack
page read and write
ED0000
heap
page read and write
3DDF000
stack
page read and write
ED4000
heap
page read and write
4C60000
direct allocation
page read and write
518F000
stack
page read and write
610000
unkown
page execute and read and write
379F000
stack
page read and write
431E000
stack
page read and write
10FF000
stack
page read and write
ED4000
heap
page read and write
4DD0000
direct allocation
page execute and read and write
ED4000
heap
page read and write
866000
unkown
page execute and read and write
4DA0000
direct allocation
page execute and read and write
2AA0000
direct allocation
page read and write
FC7000
heap
page read and write
3A5E000
stack
page read and write
2EDF000
stack
page read and write
47E1000
heap
page read and write
ED4000
heap
page read and write
3B5F000
stack
page read and write
2AA0000
direct allocation
page read and write
47E1000
heap
page read and write
469F000
stack
page read and write
F40000
heap
page read and write
4D9F000
stack
page read and write
F8B000
heap
page read and write
ED4000
heap
page read and write
47E1000
heap
page read and write
F63000
heap
page read and write
F4F000
heap
page read and write
A44000
unkown
page execute and read and write
2AA0000
direct allocation
page read and write
305E000
stack
page read and write
ED4000
heap
page read and write
5B0000
unkown
page readonly
FD0000
heap
page read and write
ED4000
heap
page read and write
37DE000
stack
page read and write
8AD000
unkown
page execute and write copy
41DE000
stack
page read and write
8AE000
unkown
page execute and write copy
2AD0000
heap
page read and write
4DD0000
direct allocation
page execute and read and write
2AA0000
direct allocation
page read and write
2AA0000
direct allocation
page read and write
47E1000
heap
page read and write
4DC0000
direct allocation
page execute and read and write
4C50000
remote allocation
page read and write
409E000
stack
page read and write
3F1F000
stack
page read and write
F8A000
heap
page read and write
4DD0000
direct allocation
page execute and read and write
F8D000
heap
page read and write
F7A000
heap
page read and write
ED4000
heap
page read and write
4DD0000
direct allocation
page execute and read and write
F45000
heap
page read and write
590000
heap
page read and write
3E1E000
stack
page read and write
4DD0000
direct allocation
page execute and read and write
3CDE000
stack
page read and write
5B1000
unkown
page execute and write copy
540E000
stack
page read and write
ED4000
heap
page read and write
2AA0000
direct allocation
page read and write
F0E000
heap
page read and write
ED4000
heap
page read and write
47E1000
heap
page read and write
F00000
heap
page read and write
4DB0000
direct allocation
page execute and read and write
341E000
stack
page read and write
F62000
heap
page read and write
2CDF000
stack
page read and write
2AC0000
direct allocation
page read and write
ED4000
heap
page read and write
4E00000
direct allocation
page execute and read and write
F7A000
heap
page read and write
BAE000
stack
page read and write
FDA000
heap
page read and write
319E000
stack
page read and write
47E1000
heap
page read and write
ED4000
heap
page read and write
2AA0000
direct allocation
page read and write
52CF000
stack
page read and write
455F000
stack
page read and write
3C9F000
stack
page read and write
2AA0000
direct allocation
page read and write
F8D000
heap
page read and write
FC4000
heap
page read and write
5A0000
heap
page read and write
3A1F000
stack
page read and write
557F000
stack
page read and write
369E000
stack
page read and write
38DF000
stack
page read and write
33DF000
stack
page read and write
F8D000
heap
page read and write
89F000
unkown
page execute and read and write
ED4000
heap
page read and write
A45000
unkown
page execute and write copy
329F000
stack
page read and write
4F4D000
stack
page read and write
365F000
stack
page read and write
There are 180 hidden memdumps, click here to show them.