IOC Report
file.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\file.exe
"C:\Users\user\Desktop\file.exe"
malicious

URLs

Name
IP
Malicious
studennotediw.stor
malicious
mobbipenju.stor
malicious
https://steamcommunity.com/profiles/76561199724331900
104.102.49.254
malicious
https://steamcommunity.com/profiles/76561199724331900/inventory/
unknown
malicious
bathdoomgaz.stor
malicious
dissapoiznw.stor
malicious
spirittunek.stor
malicious
eaglepawnoy.stor
malicious
clearancek.site
malicious
licendfilteo.site
malicious
https://sergei-esenin.com/api
172.67.206.204
malicious
https://steamcommunity.com/profiles/76561199724331900/badges
unknown
malicious
https://player.vimeo.com
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/auth_refresh.js?v=WgUxSlKTb3W1&amp
unknown
https://steamcommunity.com/?subsection=broadcasts
unknown
https://sergei-esenin.com/
unknown
https://store.steampowered.com/subscriber_agreement/
unknown
https://www.gstatic.cn/recaptcha/
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/libraries~b28b7af6
unknown
http://www.valvesoftware.com/legal.htm
unknown
https://www.youtube.com
unknown
https://community.akamai.steamstatic.com/public/css/promo/summer2017/stickers.css?v=HA2Yr5oy3FFG&amp
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/logo_valve_footer.png
unknown
https://www.google.com
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/header_menu_hamburger.png
unknown
https://steam.tv
unknown
https://community.akamai.steamstatic.com/public/shared/css/shared_responsive.css?v=sHIIcMzCffX6&
unknown
https://www.valvesoftware.com/en/contact?contact-person=Translation%20Team%20Feedback
unknown
https://steam.tvD
unknown
https://community.akamai.steamstatic.com/public/javascript/scriptaculous/_combined.js?v=OeNIgrpEF8tL
unknown
https://s.ytimg.com;
unknown
https://steam.tv/
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/header.css?v=NFoCa4OkAxRb&l=english
unknown
http://store.steampowered.com/privacy_agreement/
unknown
https://store.steampowered.com/points/shop/
unknown
https://sketchfab.com
unknown
https://lv.queniujq.cn
unknown
https://www.youtube.com/
unknown
https://community.akamai.steamstatic.com/public/css/applications/community/main.css?v=Ev2sBLgkgyWJ&a
unknown
https://avatars.akamai.steamstatic.com/fef49e7fa7e1997310d705b2a6158ff8dc1cdfeb_full.jpg
unknown
https://store.steampowered.com/privacy_agreement/
unknown
https://community.akamai.steamstatic.com/public/shared/css/shared_global.css?v=ezWS9te9Zwm9&l=en
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/tooltip.js?v=.zYHOpI1L3Rt0
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/shared_global.js?v=REEGJU1hwkYl&am
unknown
https://www.google.com/recaptcha/
unknown
https://checkout.steampowered.com/
unknown
https://community.akamai.steamstatic.com/public/css/globalv2.css?v=PAcV2zMBzzSV&l=english
unknown
https://community.akamai.steamstatic.com/public/javascript/modalv2.js?v=dfMhuy-Lrpyo&l=english
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/header_logo.png
unknown
https://avatars.akamai.steamstatic
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/profilev2.css?v=M_qL4gO2sKII&l=englis
unknown
https://community.akamai.steamstatic.com/public/javascript/jquery-1.11.1.min.js?v=.isFTSRckeNhC
unknown
https://store.steampowered.com/;
unknown
https://store.steampowered.com/about/
unknown
https://steamcommunity.com/my/wishlist/
unknown
https://community.akamai.steamstatic.com/public/javascript/global.js?v=9OzcxMXbaV84&l=english
unknown
https://help.steampowered.com/en/
unknown
https://cdn.akamai.steamstatic.com/steamcommunity/public/assets/
unknown
https://steamcommunity.com/market/
unknown
https://store.steampowered.com/news/
unknown
https://community.akamai.steamstatic.com/
unknown
https://sergei-esenin.com/apih
unknown
http://store.steampowered.com/subscriber_agreement/
unknown
https://steamcommunity.com/linkfilter/?u=http%3A%2F%2Fwww.geonames.org
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/modalContent.css?v=.VpiwkLAYt9r1
unknown
https://recaptcha.net/recaptcha/;
unknown
https://community.akamai.steamstatic.com/public/javascript/promo/stickers.js?v=upl9NJ5D2xkP&l=en
unknown
https://steamcommunity.com/discussions/
unknown
https://community.akamai.steamstatic.com/public/javascript/webui/clientcom.js?v=9yzMGndrVfY4&l=e
unknown
https://store.steampowered.com/stats/
unknown
https://medal.tv
unknown
https://broadcast.st.dl.eccdnx.com
unknown
https://community.akamai.steamstatic.com/public/images/skin_1/footerLogo_valve.png?v=1
unknown
https://store.steampowered.com/steam_refunds/
unknown
https://steamcommunity.com/login/home/?goto=profiles%2F76561199724331900
unknown
https://sergei-esenin.com/G9
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/manifest.js?v=AeTz
unknown
https://steamcommunity.com/workshop/
unknown
https://login.steampowered.com/
unknown
https://store.steampowered.com/legal/
unknown
https://community.akamai.steamstatic.com/public/javascript/reportedcontent.js?v=dAtjbcZMWhSe&l=e
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/shared_responsive_adapter.js?v=pSv
unknown
https://community.akamai.steamstatic.com/public/shared/css/motiva_sans.css?v=-DH0xTYpnVe2&l=engl
unknown
https://steambroadcast-test.akamaigB
unknown
https://recaptcha.net
unknown
https://store.steampowered.com/
unknown
https://community.akamai.steamstatic.com/public/javascript/prototype-1.7.js?v=.55t44gwuwgvw
unknown
https://community.akamai.steamstatic.com/public/images/skin_1/arrowDn9x5.gif
unknown
http://127.0.0.1:27060
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/main.js?v=10oP_O2R
unknown
https://community.akamai.steamstatic.com/public/shared/images/header/logo_steam.svg?t=962016
unknown
https://community.akamai.steamstatic.com/public/shared/css/buttons.css?v=PUJIfhtcQn7W&l=english
unknown
https://help.steampowered.com/
unknown
https://api.steampowered.com/
unknown
http://store.steampowered.com/account/cookiepreferences/
unknown
https://store.steampowered.com/mobile
unknown
https://steamcommunity.com/
unknown
https://community.akamai.steamstatic.com/public/javascript/profile.js?v=f3vWO7swdDqp&l=english
unknown
https://community.akamai.steamstatic.com/public/javascript/modalContent.js?v=f2hMA1v9Zkc8&l=engl
unknown
There are 89 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
sergei-esenin.com
172.67.206.204
malicious
licendfilteo.site
unknown
malicious
clearancek.site
unknown
malicious
steamcommunity.com
104.102.49.254
eaglepawnoy.store
unknown
bathdoomgaz.store
unknown
spirittunek.store
unknown
studennotediw.store
unknown
mobbipenju.store
unknown
dissapoiznw.store
unknown

IPs

IP
Domain
Country
Malicious
172.67.206.204
sergei-esenin.com
United States
malicious
104.102.49.254
steamcommunity.com
United States

Memdumps

Base Address
Regiontype
Protect
Malicious
F1000
unkown
page execute and read and write
malicious
409E000
stack
page read and write
11F4000
heap
page read and write
13CF000
heap
page read and write
3DDF000
stack
page read and write
13C3000
heap
page read and write
1413000
heap
page read and write
56CF000
stack
page read and write
3F5E000
stack
page read and write
4BC1000
heap
page read and write
1413000
heap
page read and write
508E000
stack
page read and write
1402000
heap
page read and write
5218000
trusted library allocation
page read and write
305E000
stack
page read and write
51E0000
direct allocation
page execute and read and write
4BB0000
direct allocation
page read and write
11F4000
heap
page read and write
3A5E000
stack
page read and write
534D000
stack
page read and write
11F4000
heap
page read and write
167E000
stack
page read and write
4BB0000
direct allocation
page read and write
4BB0000
direct allocation
page read and write
11F4000
heap
page read and write
4BB0000
direct allocation
page read and write
3B0000
unkown
page execute and read and write
11F4000
heap
page read and write
51DD000
stack
page read and write
32DE000
stack
page read and write
11F4000
heap
page read and write
3F1000
unkown
page execute and write copy
4BB0000
direct allocation
page read and write
11F4000
heap
page read and write
38DF000
stack
page read and write
140A000
heap
page read and write
341E000
stack
page read and write
4BC0000
heap
page read and write
544E000
stack
page read and write
51D0000
direct allocation
page execute and read and write
4CC0000
trusted library allocation
page read and write
445E000
stack
page read and write
42DF000
stack
page read and write
3A1F000
stack
page read and write
315F000
stack
page read and write
530D000
stack
page read and write
4BB0000
direct allocation
page read and write
51C0000
direct allocation
page execute and read and write
431E000
stack
page read and write
1402000
heap
page read and write
2D9000
unkown
page execute and read and write
586000
unkown
page execute and read and write
369E000
stack
page read and write
13FE000
heap
page read and write
518F000
stack
page read and write
587000
unkown
page execute and write copy
3F0000
unkown
page execute and write copy
3F0000
unkown
page execute and read and write
4BC1000
heap
page read and write
469F000
stack
page read and write
1377000
heap
page read and write
13E5000
heap
page read and write
4BB0000
direct allocation
page read and write
51D0000
direct allocation
page execute and read and write
13E3000
heap
page read and write
459E000
stack
page read and write
F0000
unkown
page readonly
37DE000
stack
page read and write
455F000
stack
page read and write
13B8000
heap
page read and write
13ED000
heap
page read and write
51D0000
direct allocation
page execute and read and write
41DE000
stack
page read and write
1449000
heap
page read and write
4BC1000
heap
page read and write
4BC1000
heap
page read and write
11F4000
heap
page read and write
379F000
stack
page read and write
1455000
heap
page read and write
597F000
stack
page read and write
1380000
heap
page read and write
144A000
heap
page read and write
150000
unkown
page execute and read and write
13FE000
heap
page read and write
587E000
stack
page read and write
46A0000
heap
page read and write
11F4000
heap
page read and write
5050000
direct allocation
page read and write
571E000
stack
page read and write
140C000
heap
page read and write
51A0000
direct allocation
page execute and read and write
4BC1000
heap
page read and write
11EE000
stack
page read and write
5200000
direct allocation
page execute and read and write
47EF000
stack
page read and write
3B9E000
stack
page read and write
319E000
stack
page read and write
F1000
unkown
page execute and write copy
3E1E000
stack
page read and write
4BC1000
heap
page read and write
3C9F000
stack
page read and write
5040000
remote allocation
page read and write
11AE000
stack
page read and write
301F000
stack
page read and write
11F4000
heap
page read and write
11F4000
heap
page read and write
3F1F000
stack
page read and write
11F4000
heap
page read and write
136B000
stack
page read and write
11F4000
heap
page read and write
51D0000
direct allocation
page execute and read and write
5050000
direct allocation
page read and write
4AAE000
stack
page read and write
1140000
heap
page read and write
365F000
stack
page read and write
11F4000
heap
page read and write
5040000
remote allocation
page read and write
581D000
stack
page read and write
55CE000
stack
page read and write
DDC000
stack
page read and write
329F000
stack
page read and write
4BB0000
direct allocation
page read and write
157F000
stack
page read and write
11F4000
heap
page read and write
3B5F000
stack
page read and write
11F4000
heap
page read and write
10FD000
stack
page read and write
11F4000
heap
page read and write
13E2000
heap
page read and write
11F4000
heap
page read and write
51D0000
direct allocation
page execute and read and write
4BC1000
heap
page read and write
11F4000
heap
page read and write
33DF000
stack
page read and write
138E000
heap
page read and write
5050000
direct allocation
page read and write
558E000
stack
page read and write
4BB0000
direct allocation
page read and write
51B0000
direct allocation
page execute and read and write
4BC1000
heap
page read and write
482E000
stack
page read and write
5040000
remote allocation
page read and write
3DA000
unkown
page execute and read and write
496E000
stack
page read and write
441F000
stack
page read and write
405F000
stack
page read and write
4BB0000
direct allocation
page read and write
1370000
heap
page read and write
419F000
stack
page read and write
145E000
heap
page read and write
13C6000
heap
page read and write
3CDE000
stack
page read and write
355E000
stack
page read and write
4BAF000
stack
page read and write
11F4000
heap
page read and write
4BB0000
direct allocation
page read and write
132E000
stack
page read and write
11F4000
heap
page read and write
F0000
unkown
page read and write
4BB0000
direct allocation
page read and write
51D0000
direct allocation
page execute and read and write
4BB0000
direct allocation
page read and write
4A6F000
stack
page read and write
11F4000
heap
page read and write
11F4000
heap
page read and write
548E000
stack
page read and write
5000000
heap
page read and write
351F000
stack
page read and write
2F1F000
stack
page read and write
11F4000
heap
page read and write
492F000
stack
page read and write
11F4000
heap
page read and write
138A000
heap
page read and write
391E000
stack
page read and write
4BC1000
heap
page read and write
3E2000
unkown
page execute and read and write
11F0000
heap
page read and write
4BB0000
direct allocation
page read and write
46EE000
stack
page read and write
13ED000
heap
page read and write
51F0000
direct allocation
page execute and read and write
1130000
heap
page read and write
1455000
heap
page read and write
There are 173 hidden memdumps, click here to show them.