IOC Report
A6QFRW2WiY.exe

loading gif

Files

File Path
Type
Category
Malicious
A6QFRW2WiY.exe
PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\A6QFRW2WiY.exe.log
CSV text
modified
malicious
\Device\ConDrv
ASCII text, with CRLF, LF line terminators
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\A6QFRW2WiY.exe
"C:\Users\user\Desktop\A6QFRW2WiY.exe"
malicious
C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe
"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe"
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1

URLs

Name
IP
Malicious
stogeneratmns.shop
malicious
reinforcenh.shop
malicious
ghostreedmnu.shop
malicious
https://steamcommunity.com/profiles/76561199724331900
104.102.49.254
malicious
https://steamcommunity.com/profiles/76561199724331900/inventory/
unknown
malicious
fragnantbui.shop
malicious
gutterydhowi.shop
malicious
offensivedzvju.shop
malicious
drawzhotdog.shop
malicious
https://sergei-esenin.com/api
172.67.206.204
malicious
vozmeatillu.shop
malicious
https://steamcommunity.com/profiles/76561199724331900/badges
unknown
malicious
https://community.akamai.steamstatic.com/public/javascript/global.js?v=9OzcxMXbaV84&l=english
unknown
http://ocsp.entrust.net03
unknown
http://ocsp.entrust.net02
unknown
https://sergei-esenin.com/
unknown
http://store.steampowered.com/subscriber_agreement/
unknown
https://steamcommunity.com/linkfilter/?u=http%3A%2F%2Fwww.geonames.org
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/libraries~b28b7af6
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/modalContent.css?v=.VpiwkLAYt9r1
unknown
https://community.akamai.steamstatic.com/public/css/promo/summer2017/stickers.css?v=HA2Yr5oy3FFG&amp
unknown
https://drawzhotdog.shop/api-
unknown
https://sergei-esenin.com/apiD
unknown
https://community.akamai.steamstatic.com/public/images/skin_1/footerLogo_valve.png?v=1
unknown
https://reinforcenh.shop/api
unknown
https://community.akamai.steamstatic.com/public/shared/css/shared_responsive.css?v=sHIIcMzCffX6&
unknown
https://community.akamai.steamstatic.com/public/javascript/scriptaculous/_combined.js?v=OeNIgrpEF8tL
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/manifest.js?v=AeTz
unknown
http://crl.entrust.net/ts1ca.crl0
unknown
https://store.steampowered.com/legal/
unknown
https://community.akamai.steamstatic.com/public/shared/javascript
unknown
https://steamcommunity.com/m
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/header.css?v=NFoCa4OkAxRb&l=english
unknown
https://community.akamai.steamstatic.com/public/shared/css/motiva_sans.css?v=-DH0xTYpnVe2&l=engl
unknown
http://www.entrust.net/rpa03
unknown
http://store.steampowered.com/privacy_agreement/
unknown
http://aia.entrust.net/ts1-chain256.cer01
unknown
https://vozmeatillu.shop/api
unknown
https://community.akamai.steamstatic.com/public/javascript/prototype-1.7.js?v=.55t44gwuwgvw
unknown
https://community.akamai.steamstatic.com/public/images/skin_1/arrowDn9x5.gif
unknown
https://community.akamai.steamstatic.com/public/css/applications/community/main.css?v=Ev2sBLgkgyWJ&a
unknown
https://avatars.akamai.steamstatic.com/fef49e7fa7e1997310d705b2a6158ff8dc1cdfeb_full.jpg
unknown
https://ghostreedmnu.shop/api
unknown
https://community.akamai.steamstatic.com/public/shared/css/shared_global.css?v=ezWS9te9Zwm9&l=en
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/tooltip.js?v=.zYHOpI1L3Rt0
unknown
https://sergei-esenin.com:443/api
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/main.js?v=10oP_O2R
unknown
https://community.akamai.steamstatic.com/public/shared/css/buttons.css?v=PUJIfhtcQn7W&l=english
unknown
https://community.akamai.steamstatic.com/public/css/globalv2.css?v=PAcV2zMBzzSV&l=english
unknown
http://store.steampowered.com/account/cookiepreferences/
unknown
https://steamcommunity.com/
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/profilev2.css?v=M_qL4gO2sKII&l=englis
unknown
http://crl.entrust.net/2048ca.crl0
unknown
https://community.akamai.steamstatic.com/public/javascript/jquery-1.11.1.min.js?v=.isFTSRckeNhC
unknown
https://www.entrust.net/rpa0
unknown
There are 45 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
sergei-esenin.com
172.67.206.204
malicious
fragnantbui.shop
unknown
malicious
gutterydhowi.shop
unknown
malicious
offensivedzvju.shop
unknown
malicious
stogeneratmns.shop
unknown
malicious
reinforcenh.shop
unknown
malicious
drawzhotdog.shop
unknown
malicious
ghostreedmnu.shop
unknown
malicious
vozmeatillu.shop
unknown
malicious
steamcommunity.com
104.102.49.254

IPs

IP
Domain
Country
Malicious
172.67.206.204
sergei-esenin.com
United States
malicious
104.102.49.254
steamcommunity.com
United States

Memdumps

Base Address
Regiontype
Protect
Malicious
400000
remote allocation
page execute and read and write
malicious
136E000
stack
page read and write
C20000
heap
page read and write
FD5000
heap
page read and write
1456000
heap
page read and write
FF0000
heap
page read and write
6ED000
heap
page read and write
703000
heap
page read and write
13EE000
heap
page read and write
904000
trusted library allocation
page read and write
6CA000
heap
page read and write
34D1000
trusted library allocation
page read and write
3B8000
stack
page read and write
24D1000
trusted library allocation
page execute and read and write
903000
trusted library allocation
page execute and read and write
FD0000
heap
page read and write
22C000
unkown
page readonly
466E000
stack
page read and write
2F7D000
stack
page read and write
13AA000
heap
page read and write
914000
trusted library allocation
page read and write
6C0000
heap
page read and write
F7C000
stack
page read and write
36DE000
stack
page read and write
45D000
remote allocation
page execute and read and write
8F0000
trusted library allocation
page read and write
13CF000
heap
page read and write
1463000
heap
page read and write
BFE000
stack
page read and write
30BE000
stack
page read and write
630000
heap
page read and write
2BC000
stack
page read and write
31FD000
stack
page read and write
1760000
heap
page read and write
6AE000
stack
page read and write
1370000
heap
page read and write
49B0000
trusted library allocation
page read and write
C00000
heap
page read and write
12FC000
stack
page read and write
1D0000
unkown
page readonly
6CE000
heap
page read and write
B47000
trusted library allocation
page execute and read and write
13A0000
heap
page read and write
37DF000
stack
page read and write
1300000
heap
page read and write
30FD000
stack
page read and write
2FBE000
stack
page read and write
13F1000
heap
page read and write
34D5000
trusted library allocation
page read and write
916000
trusted library allocation
page read and write
8D0000
heap
page read and write
910000
trusted library allocation
page read and write
173D000
stack
page read and write
B2E000
stack
page read and write
13D8000
heap
page read and write
13C6000
heap
page read and write
367E000
stack
page read and write
357E000
stack
page read and write
B4B000
trusted library allocation
page execute and read and write
BB0000
heap
page execute and read and write
BAE000
stack
page read and write
C10000
trusted library allocation
page execute and read and write
620000
heap
page read and write
24D3000
trusted library allocation
page read and write
1D2000
unkown
page readonly
660000
heap
page read and write
1407000
heap
page read and write
A2F000
stack
page read and write
144E000
heap
page read and write
920000
heap
page read and write
8CE000
stack
page read and write
665000
heap
page read and write
6F5000
heap
page read and write
24CE000
stack
page read and write
B3A000
trusted library allocation
page execute and read and write
2E7F000
stack
page read and write
There are 66 hidden memdumps, click here to show them.