IOC Report
file.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\file.exe
"C:\Users\user\Desktop\file.exe"
malicious

URLs

Name
IP
Malicious
studennotediw.stor
malicious
mobbipenju.stor
malicious
https://steamcommunity.com/profiles/76561199724331900
104.102.49.254
malicious
https://steamcommunity.com/profiles/76561199724331900/inventory/
unknown
malicious
bathdoomgaz.stor
malicious
dissapoiznw.stor
malicious
spirittunek.stor
malicious
eaglepawnoy.stor
malicious
clearancek.site
malicious
licendfilteo.site
malicious
https://steamcommunity.com/profiles/76561199724331900Q
unknown
malicious
https://sergei-esenin.com/api
172.67.206.204
malicious
https://player.vimeo.com
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/auth_refresh.js?v=WgUxSlKTb3W1&amp
unknown
https://store.steampowered.com/;Persistent-AuthWWW-AuthenticateVarysteamCountry=US%7Cd7fb65801182a5f
unknown
https://steamcommunity.com/?subsection=broadcasts
unknown
https://sergei-esenin.com/
unknown
https://store.steampowered.com/subscriber_agreement/
unknown
https://www.gstatic.cn/recaptcha/
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/libraries~b28b7af6
unknown
http://www.valvesoftware.com/legal.htm
unknown
https://www.youtube.com
unknown
https://community.akamai.steamstatic.com/public/css/promo/summer2017/stickers.css?v=HA2Yr5oy3FFG&amp
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/logo_valve_footer.png
unknown
https://www.google.com
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/header_menu_hamburger.png
unknown
https://community.akamai.steamstatic.com/public/shared/css/shared_responsive.css?v=sHIIcMzCffX6&
unknown
https://www.valvesoftware.com/en/contact?contact-person=Translation%20Team%20Feedback
unknown
https://eaglepawnoy.store/
unknown
https://community.akamai.steamstatic.com/public/javascript/scriptaculous/_combined.js?v=OeNIgrpEF8tL
unknown
https://s.ytimg.com;
unknown
https://steam.tv/
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/header.css?v=NFoCa4OkAxRb&l=english
unknown
http://store.steampowered.com/privacy_agreement/
unknown
https://store.steampowered.com/points/shop/
unknown
https://sergei-esenin.com/u
unknown
https://sketchfab.com
unknown
https://lv.queniujq.cn
unknown
https://www.youtube.com/
unknown
https://community.akamai.steamstatic.com/public/css/applications/community/main.css?v=Ev2sBLgkgyWJ&a
unknown
https://avatars.akamai.steamstatic.com/fef49e7fa7e1997310d705b2a6158ff8dc1cdfeb_full.jpg
unknown
https://clearancek.site/
unknown
https://store.steampowered.com/privacy_agreement/
unknown
https://community.akamai.steamstatic.com/public/shared/css/shared_global.css?v=ezWS9te9Zwm9&l=en
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/tooltip.js?v=.zYHOpI1L3Rt0
unknown
https://sergei-esenin.com:443/api
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/shared_global.js?v=REEGJU1hwkYl&am
unknown
https://www.google.com/recaptcha/
unknown
https://checkout.steampowered.com/
unknown
https://community.akamai.steamstatic.com/public/css/globalv2.css?v=PAcV2zMBzzSV&l=english
unknown
https://community.akamai.steamstatic.com/public/javascript/modalv2.js?v=dfMhuy-Lrpyo&l=english
unknown
https://sergei-esenin.com/U
unknown
https://dissapoiznw.store/
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/header_logo.png
unknown
https://avatars.akamai.steamstatic
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/profilev2.css?v=M_qL4gO2sKII&l=englis
unknown
https://community.akamai.steamstatic.com/public/javascript/jquery-1.11.1.min.js?v=.isFTSRckeNhC
unknown
https://store.steampowered.com/;
unknown
https://store.steampowered.com/about/
unknown
https://steamcommunity.com/my/wishlist/
unknown
https://community.akamai.steamstatic.com/public/javascript/global.js?v=9OzcxMXbaV84&l=english
unknown
https://help.steampowered.com/en/
unknown
https://cdn.akamai.steamstatic.com/steamcommunity/public/assets/
unknown
https://steamcommunity.com/market/
unknown
https://store.steampowered.com/news/
unknown
https://community.akamai.steamstatic.com/
unknown
http://store.steampowered.com/subscriber_agreement/
unknown
https://steamcommunity.com/linkfilter/?u=http%3A%2F%2Fwww.geonames.org
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/modalContent.css?v=.VpiwkLAYt9r1
unknown
https://recaptcha.net/recaptcha/;
unknown
https://community.akamai.steamstatic.com/public/javascript/promo/stickers.js?v=upl9NJ5D2xkP&l=en
unknown
https://steamcommunity.com/discussions/
unknown
https://community.akamai.steamstatic.com/public/javascript/webui/clientcom.js?v=9yzMGndrVfY4&l=e
unknown
https://store.steampowered.com/stats/
unknown
https://medal.tv
unknown
https://broadcast.st.dl.eccdnx.com
unknown
https://community.akamai.steamstatic.com/public/images/skin_1/footerLogo_valve.png?v=1
unknown
https://store.steampowered.com/steam_refunds/
unknown
https://steamcommunity.com/login/home/?goto=profiles%2F76561199724331900
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/manifest.js?v=AeTz
unknown
https://steamcommunity.com/workshop/
unknown
https://login.steampowered.com/
unknown
https://store.steampowered.com/legal/
unknown
https://community.akamai.steamstatic.com/public/javascript/reportedcontent.js?v=dAtjbcZMWhSe&l=e
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/shared_responsive_adapter.js?v=pSv
unknown
https://community.akamai.steamstatic.com/public/shared/css/motiva_sans.css?v=-DH0xTYpnVe2&l=engl
unknown
https://recaptcha.net
unknown
https://store.steampowered.com/
unknown
https://community.akamai.steamstatic.com/public/javascript/prototype-1.7.js?v=.55t44gwuwgvw
unknown
https://community.akamai.steamstatic.com/public/images/skin_1/arrowDn9x5.gif
unknown
http://127.0.0.1:27060
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/main.js?v=10oP_O2R
unknown
https://community.akamai.steamstatic.com/public/shared/images/header/logo_steam.svg?t=962016
unknown
https://community.akamai.steamstatic.com/public/shared/css/buttons.css?v=PUJIfhtcQn7W&l=english
unknown
https://help.steampowered.com/
unknown
https://api.steampowered.com/
unknown
http://store.steampowered.com/account/cookiepreferences/
unknown
https://store.steampowered.com/mobile
unknown
https://steamcommunity.com/
unknown
https://community.akamai.steamstatic.com/public/javascript/profile.js?v=f3vWO7swdDqp&l=english
unknown
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
sergei-esenin.com
172.67.206.204
malicious
licendfilteo.site
unknown
malicious
clearancek.site
unknown
malicious
steamcommunity.com
104.102.49.254
eaglepawnoy.store
unknown
bathdoomgaz.store
unknown
spirittunek.store
unknown
studennotediw.store
unknown
mobbipenju.store
unknown
dissapoiznw.store
unknown

IPs

IP
Domain
Country
Malicious
172.67.206.204
sergei-esenin.com
United States
malicious
104.102.49.254
steamcommunity.com
United States

Memdumps

Base Address
Regiontype
Protect
Malicious
831000
unkown
page execute and read and write
malicious
830000
unkown
page read and write
35EE000
stack
page read and write
45F1000
heap
page read and write
3B0000
heap
page read and write
4C00000
direct allocation
page execute and read and write
45F1000
heap
page read and write
412E000
stack
page read and write
436F000
stack
page read and write
4F7E000
stack
page read and write
DEB000
heap
page read and write
E2A000
heap
page read and write
45F1000
heap
page read and write
DF3000
heap
page read and write
4E7E000
stack
page read and write
4C00000
direct allocation
page execute and read and write
DC0000
heap
page read and write
3FEE000
stack
page read and write
CD4000
unkown
page execute and read and write
DEB000
heap
page read and write
50BF000
stack
page read and write
820000
direct allocation
page read and write
B38000
unkown
page execute and write copy
4A80000
direct allocation
page read and write
AF6000
unkown
page execute and read and write
45EF000
stack
page read and write
DA1000
heap
page read and write
45F1000
heap
page read and write
3AAF000
stack
page read and write
45F1000
heap
page read and write
50D0000
remote allocation
page read and write
DA5000
heap
page read and write
4C00000
direct allocation
page execute and read and write
820000
direct allocation
page read and write
336E000
stack
page read and write
4C00000
direct allocation
page execute and read and write
422F000
stack
page read and write
521E000
stack
page read and write
DE2000
heap
page read and write
34AE000
stack
page read and write
D97000
heap
page read and write
820000
direct allocation
page read and write
CD5000
unkown
page execute and write copy
F5E000
stack
page read and write
3D2F000
stack
page read and write
820000
direct allocation
page read and write
B21000
unkown
page execute and read and write
DC0000
heap
page read and write
DEB000
heap
page read and write
511D000
stack
page read and write
DC3000
heap
page read and write
382F000
stack
page read and write
39AE000
stack
page read and write
3A0000
heap
page read and write
372E000
stack
page read and write
DAE000
heap
page read and write
4BD0000
direct allocation
page execute and read and write
30AE000
stack
page read and write
45F1000
heap
page read and write
830000
unkown
page readonly
820000
direct allocation
page read and write
A17000
unkown
page execute and read and write
396F000
stack
page read and write
DC0000
heap
page read and write
B37000
unkown
page execute and read and write
45F0000
heap
page read and write
45F1000
heap
page read and write
2F6F000
stack
page read and write
45F1000
heap
page read and write
2867000
heap
page read and write
536D000
stack
page read and write
820000
direct allocation
page read and write
DA9000
heap
page read and write
2CEF000
stack
page read and write
E30000
heap
page read and write
820000
direct allocation
page read and write
DAE000
heap
page read and write
4BE0000
direct allocation
page execute and read and write
820000
direct allocation
page read and write
4A80000
direct allocation
page read and write
45F1000
heap
page read and write
3EAE000
stack
page read and write
DAE000
heap
page read and write
D93000
heap
page read and write
2E2F000
stack
page read and write
53CE000
stack
page read and write
45F1000
heap
page read and write
2BAF000
stack
page read and write
105F000
stack
page read and write
DF5000
heap
page read and write
45F1000
heap
page read and write
820000
direct allocation
page read and write
2D2E000
stack
page read and write
D5E000
stack
page read and write
35AF000
stack
page read and write
4C10000
direct allocation
page execute and read and write
DE6000
heap
page read and write
4BBF000
stack
page read and write
3D6E000
stack
page read and write
50D0000
remote allocation
page read and write
E44000
heap
page read and write
DF5000
heap
page read and write
30EE000
stack
page read and write
4A80000
direct allocation
page read and write
386E000
stack
page read and write
45F1000
heap
page read and write
890000
unkown
page execute and read and write
3FAF000
stack
page read and write
2AAE000
stack
page read and write
4600000
heap
page read and write
D1E000
stack
page read and write
36EF000
stack
page read and write
45F1000
heap
page read and write
D6A000
heap
page read and write
33C000
stack
page read and write
820000
direct allocation
page read and write
4C20000
direct allocation
page execute and read and write
43AE000
stack
page read and write
45F1000
heap
page read and write
6FD000
stack
page read and write
DA8000
heap
page read and write
820000
direct allocation
page read and write
390000
heap
page read and write
2860000
heap
page read and write
4E3D000
stack
page read and write
44EE000
stack
page read and write
426E000
stack
page read and write
296F000
stack
page read and write
DC3000
heap
page read and write
46F0000
trusted library allocation
page read and write
332F000
stack
page read and write
DF5000
heap
page read and write
45F1000
heap
page read and write
820000
direct allocation
page read and write
395000
heap
page read and write
4C00000
direct allocation
page execute and read and write
2FAE000
stack
page read and write
4C0D000
stack
page read and write
B37000
unkown
page execute and write copy
346F000
stack
page read and write
40EF000
stack
page read and write
DD7000
heap
page read and write
45F1000
heap
page read and write
44AF000
stack
page read and write
DF3000
heap
page read and write
DA1000
heap
page read and write
3C2E000
stack
page read and write
DEB000
heap
page read and write
54CF000
stack
page read and write
DE6000
heap
page read and write
4BF0000
direct allocation
page execute and read and write
DC3000
heap
page read and write
2840000
heap
page read and write
2E6E000
stack
page read and write
DA5000
heap
page read and write
820000
direct allocation
page read and write
2A6F000
stack
page read and write
D97000
heap
page read and write
80E000
stack
page read and write
4C44000
trusted library allocation
page read and write
B28000
unkown
page execute and read and write
DEB000
heap
page read and write
3AEE000
stack
page read and write
45F1000
heap
page read and write
DF5000
heap
page read and write
4FBE000
stack
page read and write
4C30000
direct allocation
page execute and read and write
D6E000
heap
page read and write
3BEF000
stack
page read and write
4A6D000
stack
page read and write
526D000
stack
page read and write
322E000
stack
page read and write
E3B000
heap
page read and write
50D0000
remote allocation
page read and write
831000
unkown
page execute and write copy
31EF000
stack
page read and write
DA9000
heap
page read and write
4ABE000
stack
page read and write
45F1000
heap
page read and write
283C000
stack
page read and write
810000
heap
page read and write
3E6F000
stack
page read and write
45F1000
heap
page read and write
820000
direct allocation
page read and write
4D3D000
stack
page read and write
2BEE000
stack
page read and write
4C00000
direct allocation
page execute and read and write
D60000
heap
page read and write
There are 178 hidden memdumps, click here to show them.